CVE-2020-15676Cross-site Scripting in Mozilla Firefox

CWE-79Cross-site Scripting11 documents9 sources
Severity
6.1MEDIUMNVD
EPSS
1.3%
top 20.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 1
Latest updateMay 24

Description

Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages8 packages

CVEListV5mozilla/firefoxunspecified81
NVDmozilla/firefox< 81.0
CVEListV5mozilla/firefox_esrunspecified78.3
CVEListV5mozilla/thunderbirdunspecified78.3

Also affects: Debian Linux 10.0, 9.0

🔴Vulnerability Details

3
GHSA
GHSA-m5jf-7x3g-f295: Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasti2022-05-24
OSV
CVE-2020-15676: Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasti2020-10-01
CVEList
CVE-2020-15676: Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasti2020-10-01

📋Vendor Advisories

6
Ubuntu
Firefox vulnerabilities2020-09-28
Red Hat
Mozilla: XSS when pasting attacker-controlled data into a contenteditable element2020-09-22
Debian
CVE-2020-15676: firefox - Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer...2020
Mozilla
Mozilla Foundation Security Advisory 2020-42: CVE-2020-15676
Mozilla
Mozilla Foundation Security Advisory 2020-44: CVE-2020-15676

💬Community

1
Bugzilla
CVE-2020-15676 Mozilla: XSS when pasting attacker-controlled data into a contenteditable element2020-09-22
CVE-2020-15676 — Cross-site Scripting in Mozilla | cvebase