Back

MEDIUM

Mozilla: Incorrect parsing of template tag could result in JavaScript injection

Published Mar 2, 2020

Description

If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but is potentially a risk in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.

Affected products

Remediation

No remediation recorded yet.

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Mar 2, 2020
Updated Aug 4, 2024
Reserved Jan 10, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 11, 2020
ENISA EUVD
Assigner mozilla
Published Mar 2, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-27945