Web Hack List

Collected research

CVE-2018-5175: Universal CSP strict-dynamic bypass in Firefox

Firefox exposed a bundled require.js through a web-accessible resource URI, and browser extension resources are loaded regardless of a page's Content Security Policy. Any site protected by script-src strict-dynamic could therefore have its policy bypassed from a simple HTML injection, turning it into full script execution.

Record

Researcher
Masato Kinugawa
Published by
mksben.l0.cm
Format
Advisory
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Masato Kinugawa, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .