← Back to CVE List

CVE-2018-12370

Published: 2018-10-18T13:29Z
Last Modified: 2024-11-21T03:45Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited if loaded by a malicious site while Reader mode is active, bypassing CSRF protections. This vulnerability affects Firefox < 61. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt