PT-2018-3044 · Mozilla+3 · Firefox+3

Abdulrahman Alqabandi

·

Published

2018-05-09

·

Updated

2024-12-12

·

CVE-2018-5172

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 60
Description The issue arises when a user pastes script content from the clipboard into the Live Bookmarks page or the PDF viewer while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user into copying and pasting malicious script content, which could then run with the context of either page. However, it does not allow for privilege escalation. The vulnerability can be exploited by a remote attacker using a specially crafted website to execute arbitrary code.
Recommendations For versions prior to 60, update to version 60 or later to resolve the issue. As a temporary workaround, consider avoiding the paste function in the Live Bookmarks page and the PDF viewer when viewing RSS feeds or PDF files from untrusted sources. Restrict access to these features to minimize the risk of exploitation.

Fix

Special Elements Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1787
ALT-PU-2018-1854
BDU:2019-03512
CVE-2018-5172
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2019:2872-1
USN-3645-1
USN-3645-2

Affected Products

Alt Linux
Firefox
Suse
Ubuntu