PT-2019-4608 · Mozilla+5 · Firefox Esr+7

Luigi Gubello

·

Published

2019-07-09

·

Updated

2025-09-29

·

CVE-2019-11730

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 68 Firefox ESR versions prior to 60.8 Thunderbird versions prior to 60.8
Description A vulnerability exists where opening a locally saved HTML file can allow access to other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may be uploaded to a server. This issue can be exploited in combination with a popular Android messaging app to read attachments the victim received from other correspondents.
Recommendations For Firefox versions prior to 68, update to version 68 or later to resolve the issue. For Firefox ESR versions prior to 60.8, update to version 60.8 or later to resolve the issue. For Thunderbird versions prior to 60.8, update to version 60.8 or later to resolve the issue. As a temporary workaround, consider avoiding opening locally saved HTML files from untrusted sources until a patch is available. Restrict access to sensitive files and directories to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019_2799
ALSA-2019_4273
ALSA-2025_16880
ALT-PU-2019-2231
ALT-PU-2019-2233
ALT-PU-2019-2249
ALT-PU-2019-2259
ALT-PU-2019-2301
ALT-PU-2019-2324
ALT-PU-2019-2479
ALT-PU-2019-2486
ALT-PU-2020-1166
ALT-PU-2020-1515
BDU:2020-00723
CESA-2019_1763
CESA-2019_1764
CESA-2019_1765
CESA-2019_1775
CESA-2019_1777
CESA-2019_1799
CVE-2019-11730
DLA-1869-1
DLA-1870-1
DSA-4479-1
DSA-4482-1
ELSA-2019-1763
ELSA-2019-1764
ELSA-2019-1765
ELSA-2019-1775
ELSA-2019-1777
ELSA-2019-1799
MGASA-2019-0211
MGASA-2019-0212
MGASA-2019-0213
MGASA-2019-0272
OPENSUSE-SU-2019:1782-1
OPENSUSE-SU-2019:1811-1
OPENSUSE-SU-2019:1813-1
OPENSUSE-SU-2019:1990-1
OPENSUSE-SU-2019:2248-1
OPENSUSE-SU-2019:2249-1
OPENSUSE-SU-2019_1782-1
OPENSUSE-SU-2019_1811-1
OPENSUSE-SU-2019_1813-1
OPENSUSE-SU-2019_2248-1
OPENSUSE-SU-2019_2249-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
RHSA-2019:1763
RHSA-2019:1764
RHSA-2019:1765
RHSA-2019:1775
RHSA-2019:1777
RHSA-2019:1799
RHSA-2019_1763
RHSA-2019_1764
RHSA-2019_1765
RHSA-2019_1775
RHSA-2019_1777
RHSA-2019_1799
SUSE-SU-2019:14124-1
SUSE-SU-2019:14246-1
SUSE-SU-2019:1861-1
SUSE-SU-2019:1861-2
SUSE-SU-2019:1861-3
SUSE-SU-2019:1869-1
SUSE-SU-2019:1960-1
SUSE-SU-2019:2515-1
SUSE-SU-2019:2620-1
SUSE-SU-2019_14124-1
SUSE-SU-2019_14246-1
SUSE-SU-2019_1861-1
SUSE-SU-2019_1869-1
SUSE-SU-2019_2620-1
USN-4054-1
USN-4054-2
USN-4064-1

Affected Products

Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird
Ubuntu