← Back to CVE List

CVE-2018-18499

Published: 2019-02-28T18:29Z
Last Modified: 2024-11-21T03:56Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt