CVEs Blog | G5 Cyber Security

CVE-2020-15676 – Firefox sometimes ran the onload handler for SVG elements that the DOM sa

Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.   Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15676 Reference (s):

Exit mobile version