Other nomination
CVE-2018-5175: Universal CSP strict-dynamic bypass in Firefox
Firefox exposed a bundled require.js through a web-accessible resource URI, and browser extension resources are loaded regardless of a page's Content Security Policy. Any site protected by script-src strict-dynamic could therefore have its policy bypassed from a simple HTML injection, turning it into full script execution.
Record
- Researcher
- Masato Kinugawa
- Format
- Advisory
In the archive
- Nominated for the 2016–17 Top 10 Web Hacking Techniques
- Nominated for the 2018 Top 10 Web Hacking Techniques
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Masato Kinugawa, first published at the original source. Preserved copies are kept so the citation survives its host.