CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. It affects Firefox.
CVE
CVE-2018-12370
Severity
HIGH
CVSS
8.8
EPSS
1.13%
Firefox
Original NVD Description
In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited if loaded by a malicious site while Reader mode is active, bypassing CSRF protections. This vulnerability affects Firefox < 61.
Related CVEs
Other vulnerabilities affecting the same vendor(s)