CVE-2017-5387

Severity CVSS v4.0:
Pending analysis
Type:
CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory
Publication date:
11/06/2018
Last modified:
07/08/2018

Description

The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on a "" tag refers to a file that does not exist if the source page is loaded locally. This vulnerability affects Firefox

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 51.0 (excluding)