← back
CVE-2018-5105

CVE-2018-5105

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.4%
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
nono source reports it
WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file running with local user privileges without explicit user consent. This vulnerability affects Firefox < 58.
Affected products
Mozilla · Firefox