Field Assessment
AI analysis pending.
CVE
CVE-2018-5137
Severity
HIGH
CVSS
7.5
EPSS
1.68%
Firefox
Original Filing — NVD Description
A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a maliciously crafted path string to reference the resources. Note: this vulnerability does not affect WebExtensions. This vulnerability affects Firefox < 59.