PT-2019-3408 · Mozilla+5 · Firefox Esr+7

Abdulrahman Alqabandi

·

Published

2019-05-21

·

Updated

2024-12-12

·

CVE-2019-11698

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 60.7 Firefox versions prior to 67 Firefox ESR versions prior to 60.7
Description A vulnerability exists where if a specially crafted hyperlink is dragged and dropped into the bookmark bar or sidebar, and the resulting bookmark is then dragged and dropped into the web content area, it can execute an arbitrary query of a user's browser history and transmit it to the content page via event data. This allows a malicious site to steal a user's browser history.
Recommendations For Thunderbird versions prior to 60.7, update to version 60.7 or later to resolve the issue. For Firefox versions prior to 67, update to version 67 or later to resolve the issue. For Firefox ESR versions prior to 60.7, update to version 60.7 or later to resolve the issue.

Exploit

Fix

RCE

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1876
ALT-PU-2019-1879
ALT-PU-2019-1941
ALT-PU-2019-2324
ALT-PU-2019-2479
ALT-PU-2019-2486
BDU:2019-03561
CESA-2019_1265
CESA-2019_1267
CESA-2019_1269
CESA-2019_1308
CESA-2019_1309
CESA-2019_1310
CVE-2019-11698
DLA-1800-1
DLA-1806-1
DSA-4448-1
DSA-4451-1
MGASA-2019-0190
MGASA-2019-0191
OPENSUSE-SU-2019:1534-1
OPENSUSE-SU-2019:1664-1
OPENSUSE-SU-2019_1484-1
OPENSUSE-SU-2019_1534-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
RHSA-2019:1265
RHSA-2019:1267
RHSA-2019:1269
RHSA-2019:1308
RHSA-2019:1309
RHSA-2019:1310
RHSA-2019_1265
RHSA-2019_1267
RHSA-2019_1269
RHSA-2019_1308
RHSA-2019_1309
RHSA-2019_1310
SUSE-SU-2019:1388-1
SUSE-SU-2019:1405-1
SUSE-SU-2019:1458-1
SUSE-SU-2019_1405-1
USN-3991-1
USN-3991-2
USN-3991-3
USN-3997-1

Affected Products

Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird
Ubuntu