Collected research
CVE-2018-5175: Universal CSP strict-dynamic bypass in Firefox
Firefox exposed a bundled require.js through a web-accessible resource URI, and browser extension resources are loaded regardless of a page's Content Security Policy. Any site protected by script-src strict-dynamic could therefore have its policy bypassed from a simple HTML injection, turning it into full script execution.
Record
- Researcher
- Masato Kinugawa
- Published by
- mksben.l0.cm
- Format
- Advisory
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Masato Kinugawa, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .