CVE-2020-26951 Information
Jun 07, 2022
cve
Description
A parsing and event loading mismatch in Firefox’s SVG code could have allowed load events to fire even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83 Firefox ESR < 78.5 and Thunderbird < 78.5.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://www.mozilla.org/security/advisories/mfsa2020-50/ https://www.mozilla.org/security/advisories/mfsa2020-51/ https://www.mozilla.org/security/advisories/mfsa2020-52/ https://bugzilla.mozilla.org/show_bug.cgi?id=1667113
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: