CVE-2019-11701: XSS
Last updated 25 August 2025
Other sources
The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. Note: this issue only affects users with an account on the vulnerable service. Other users are unaffected.. This vulnerability affects Firefox < 67.
— Launchpad
The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. Note: this issue only affects users with an account on the vulnerable service. Other users are unaffected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 67 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 152.0-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-11701?
CVE-2019-11701 is a vulnerability in the default webcal: protocol handler in Mozilla Firefox that can be exploited for cross-site scripting (XSS) attacks.
Who is affected by CVE-2019-11701?
Only users with an account on the vulnerable service are affected by CVE-2019-11701. Other users are unaffected.
What is the severity of CVE-2019-11701?
CVE-2019-11701 has a severity rating of 6.1, which is considered medium.
How can I fix CVE-2019-11701 in Mozilla Firefox?
To fix CVE-2019-11701, update your Mozilla Firefox browser to version 67 or higher.
Where can I find more information about CVE-2019-11701?
You can find more information about CVE-2019-11701 on the Mozilla security advisory page: [link](https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/).