CVE-2018-5168: Medium severity Mozilla Thunderbird vulnerability
Last updated 25 August 2025
Other sources
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
— Launchpad
Sites can bypass security checks on permissions to install lightweight themes by manipulating the baseURI property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5168
— Red Hat
Sites can bypass security checks on permissions to install lightweight themes by manipulating the baseURI property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5183
- CVE-2018-5184
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5159
- CVE-2018-5161
- CVE-2018-5162
- CVE-2018-5170
- CVE-2018-5168
- CVE-2018-5174
- CVE-2018-5178
- CVE-2018-5185
- CVE-2018-5150
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2018-5168.
Which software is affected by this vulnerability?
This vulnerability affects Mozilla Firefox ESR version 52.8 and Mozilla Firefox version up to 60.0.
How can a malicious site exploit this vulnerability?
A malicious site can exploit this vulnerability by manipulating the "baseURI" property of the theme element to bypass security checks and install a theme without user interaction.
What are the potential consequences of this vulnerability?
This vulnerability could allow a malicious site to install a theme containing offensive or embarrassing images.
What is the severity of this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 5.3.