NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html;/json Content-Type value.
Link | Tags |
---|---|
https://noscript.net/getit#classic | release notes |
https://twitter.com/Zerodium/status/1039127214602641409 | third party advisory |
https://www.zdnet.com/article/exploit-vendor-drops-tor-browser-zero-day-on-twitter/ | third party advisory |