First published: Tue Nov 17 2020(Updated: )
In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <78.5 | 78.5 |
<83 | 83 | |
<78.5 | 78.5 | |
<78.5 | 78.5 | |
Mozilla Firefox | <83.0 | |
Mozilla Firefox ESR | <78.5 | |
Mozilla Thunderbird | <78.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2020-26956.
The affected software includes Mozilla Firefox ESR version up to 78.5, Mozilla Firefox version up to 83, and Mozilla Thunderbird version up to 78.5.
The severity of CVE-2020-26956 is medium (severity value: 4).
CVE-2020-26956 can lead to XSS (cross-site scripting) by allowing existing SVG event handlers to remain after removing HTML elements during sanitization.
To fix CVE-2020-26956, update to the appropriate version of Mozilla Firefox ESR or Mozilla Thunderbird.