CVE-2018-5172 — Cross-site Scripting in Mozilla Firefox
Severity
4.3MEDIUMNVD
OSV9.8
EPSS
0.7%
top 28.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 13
Description
The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste malicious script content that could then run with the context of either page but does not allow for privilege escalation. This vulnerability affects Firefox < 60.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages5 packages
Also affects: Ubuntu Linux 14.04, 16.04, 17.10, 18.04
🔴Vulnerability Details
5GHSA▶
GHSA-w752-w9m4-4289: The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feed↗2022-05-13
OSV▶
CVE-2018-5172: The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feed↗2018-05-11
📋Vendor Advisories
4Red Hat
▶
Debian▶
CVE-2018-5172: firefox - The Live Bookmarks page and the PDF viewer can run injected script content if a ...↗2018
💬Community
1Bugzilla▶
CVE-2018-5172 Mozilla: Pasted script from clipboard can run in the Live Bookmarks page or PDF viewer↗2018-05-09