AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-12397

HIGH · CVSS 7.1 EPSS 0.37%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-02-28 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.1. It affects Firefox.

CVE
CVE-2018-12397
Severity
HIGH
CVSS
7.1
EPSS
0.37%
Firefox

Original NVD Description

A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

Related CVEs

Other vulnerabilities affecting the same vendor(s)