← Back to CVE List

CVE-2018-5133

Published: 2018-06-11T21:29Z
Last Modified: 2024-11-21T04:08Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It will be executed if a user loads "chrome://browser/content/preferences/in-content/preferences.xul" directly in a tab and executes a search. This stored preference is also executed whenever an EME video player plugin displays a CDM-disabled message as a notification message. This vulnerability affects Firefox < 59. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt