CVE-2020-26956Cross-site Scripting in Mozilla Firefox

CWE-79Cross-site Scripting12 documents8 sources
Severity
6.1MEDIUMNVD
EPSS
0.4%
top 37.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9
Latest updateMay 24

Description

In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages7 packages

CVEListV5mozilla/firefox< 83
NVDmozilla/firefox< 83.0
CVEListV5mozilla/firefox_esr< 78.5
CVEListV5mozilla/thunderbird< 78.5

🔴Vulnerability Details

3
GHSA
GHSA-2rfm-q54c-ww9j: In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS2022-05-24
OSV
CVE-2020-26956: In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS2020-12-09
CVEList
CVE-2020-26956: In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS2020-12-09

📋Vendor Advisories

8
Ubuntu
Thunderbird vulnerabilities2020-11-25
Ubuntu
Firefox vulnerabilities2020-11-19
Ubuntu
Firefox vulnerabilities2020-11-18
Red Hat
Mozilla: XSS through paste (manual and clipboard API)2020-11-17
Debian
CVE-2020-26956: firefox - In some cases, removing HTML elements during sanitization would keep existing SV...2020
CVE-2020-26956 — Cross-site Scripting in Mozilla | cvebase