The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to bypass an HTML Sanitizer. This vulnerability affects Firefox < 86.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefoxUpgrade librewolf | Aug 22, 2024 | Feb 26, 2021 |
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade www-client/firefox-bin. | May 3, 2021 | Feb 26, 2021 |
| Mfsa2021 07 | — | Upgrade to Mozilla Firefox version 86.0Upgrade to the latest version of Mozilla Firefox | Feb 24, 2021 | Feb 23, 2021 |
| Ubuntu | — | Upgrade firefox | Feb 27, 2021 | Feb 26, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub