Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mathias Wu

#49581of 53,630
5Total CVSS
Vulnerabilities · 1
PT-2018-3171
5.0
2018-10-23
Mozilla · Firefox · CVE-2018-12399
**Name of the Vulnerable Software and Affected Versions** Firefox versions prior to 63 **Description** The issue is related to the registration of new protocol handlers, where the API accepts a `title` argument that can be misleading about the domain registering the handler. This may lead to users approving a protocol handler they otherwise would not have. The vulnerability is also described as being related to insufficient access control in the Firefox browser API, which could allow a remote attacker to substitute the user interface using a specially crafted `title` argument. **Recommendations** For versions prior to 63, update to version 63 or later to resolve the issue. As a temporary workaround, consider restricting the approval of new protocol handlers to minimize the risk of exploitation.