### [CVE-2018-12373](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12373) ![](https://img.shields.io/static/v1?label=Product&message=Thunderbird&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3C%2052.9%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=S%2FMIME%20plaintext%20can%20be%20leaked%20through%20HTML%20reply%2Fforward&color=brighgreen) ### Description dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderbird < 52.9. ### POC #### Reference - https://usn.ubuntu.com/3714-1/ - https://usn.ubuntu.com/3714-1/ #### Github No PoCs found on GitHub currently.