CVE-2019-11718

Source
Severity Medium
Remote Yes
Type Insufficient validation
Description
In Firefox before 68.0, Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stream, such as browsing history, if the Snipper Service were compromised.
Group Package Affected Fixed Severity Status Ticket
AVG-1002 firefox 67.0.4-2 68.0-1 Critical Fixed
Date Advisory Group Package Severity Description
17 Jul 2019 ASA-201907-4 AVG-1002 firefox Critical multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2019-21/#CVE-2019-11718
https://bugzilla.mozilla.org/show_bug.cgi?id=1408349