Self-XSS in Mozilla Firefox - CVE-2018-5143

 

Self-XSS in Mozilla Firefox - CVE-2018-5143

Published: March 13, 2018


Vulnerability identifier: #VU10986
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2018-5143
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct self-XSS attack.

The weakness exists due to URLs using javascript: have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks. A remote attacker can supply URL with embedded tab into addressbar and become socially engineered to run an XSS attack against themselves.

Affected software

Mozilla Firefox
firefox (Ubuntu package)

How to mitigate CVE-2018-5143

Update to version 59.0.

firefox (Ubuntu package) - addressed in versions 59.0+build5-0ubuntu0.14.04.1, 59.0+build5-0ubuntu0.16.04.1, 59.0+build5-0ubuntu0.17.10.1

External References

Related Security Bulletins