Comment 0 for bug 1747209

Revision history for this message
Mark Sapiro (msapiro) wrote :

CVE-2018-5950

A crafted URL for a user options page can cause a browser to execute arbitrary script encoded in the URL.

Also, in developing a fix for this issue it was discovered that a user options URL with a VARHELP query fragment would display the user options page without requiring login. No changes could be made and the settings revealed are not particularly sensitive, but this could be used to fish for membership on a list with a private roster.