Self-XSS in Mozilla Firefox - CVE-2018-5143
Published: March 13, 2018
Vulnerability identifier: #VU10986
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2018-5143
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to conduct self-XSS attack.
The weakness exists due to URLs using javascript: have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks
The weakness exists due to URLs using javascript: have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks
. A remote attacker can supply URL
with embedded tab into addressbar and become socially engineered to run
an XSS attack against themselves. Affected software
Mozilla Firefox
firefox (Ubuntu package)
firefox (Ubuntu package)
How to mitigate CVE-2018-5143
Update to version 59.0.
firefox (Ubuntu package) - addressed in versions 59.0+build5-0ubuntu0.14.04.1, 59.0+build5-0ubuntu0.16.04.1, 59.0+build5-0ubuntu0.17.10.1