CVE-2018-5172: XSS
Last updated 25 August 2025
Other sources
The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste malicious script content that could then run with the context of either page but does not allow for privilege escalation.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5159
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5168
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5174
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
- CVE-2018-5150
Frequently Asked Questions
What is CVE-2018-5172?
CVE-2018-5172 is a vulnerability that allows the execution of injected script content when a user pastes script from the clipboard into the Live Bookmarks page or the PDF viewer in Firefox.
Who is affected by CVE-2018-5172?
Users of Mozilla Firefox versions up to 60.0 and Ubuntu Linux versions 14.04, 16.04, 17.10, and 18.04 with Firefox versions up to 60.0 are affected.
What is the severity of CVE-2018-5172?
CVE-2018-5172 has a severity rating of medium.
How can I protect myself from CVE-2018-5172?
Update your Mozilla Firefox to version 60.0 or later and ensure that you are using the latest version of Ubuntu Linux.
Where can I get more information about CVE-2018-5172?
You can find more information about CVE-2018-5172 on the Mozilla Bugzilla, Mozilla Security Advisories, and SecurityFocus websites.