When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-firefox-esralpine-linux-upgrade-firefoxalpine-linux-upgrade-librewolf | Jun 11, 2020 | Jan 8, 2020 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-thunderbirdamazon-linux-ami-2-upgrade-thunderbird-debuginfo | Apr 27, 2020 | Jan 8, 2020 | |
| Arch Linux | View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗ | arch-linux-upgrade-latest | Jul 11, 2025 | Jan 8, 2020 |
| Centos_linux | — | centos-upgrade-firefoxcentos-upgrade-firefox-debuginfocentos-upgrade-firefox-debugsourcecentos-upgrade-thunderbirdcentos-upgrade-thunderbird-debuginfocentos-upgrade-thunderbird-debugsource | Jan 14, 2020 | Jan 8, 2020 |
| Debian | debian-upgrade-firefox-esrdebian-upgrade-thunderbird | Jan 13, 2020 | Jan 8, 2020 | |
| Gentoo Linux | gentoo-linux-upgrade-www-client-firefoxgentoo-linux-upgrade-www-client-firefox-bin | Mar 13, 2020 | Jan 8, 2020 | |
| Mfsa2020 01 | mozilla-firefox-upgrade-72_0 | Jan 8, 2020 | Jan 7, 2020 | |
| Mfsa2020 02 | mozilla-firefox-esr-upgrade-68_4 | Jan 8, 2020 | Jan 7, 2020 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-68_4_1 | Jan 13, 2020 | Jan 8, 2020 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-mail-thunderbird-68-4-1-11-4-18-0-1-3-0oracle-solaris-11-4-upgrade-mail-thunderbird-plugin-thunderbird-lightning-68-4-1-11-4-18-0-1-3-0oracle-solaris-11-4-upgrade-web-browser-firefox-68-4-1-11-4-18-0-1-3-0oracle-solaris-11-4-upgrade-web-data-firefox-bookmarks-68-4-1-11-4-18-0-1-3-0 | Jan 19, 2021 | Jan 8, 2020 | |
| Oracle_linux | — | oracle-linux-upgrade-firefoxoracle-linux-upgrade-thunderbird | Jan 19, 2020 | Jan 7, 2020 |
| Redhat_linux | redhat-upgrade-firefoxredhat-upgrade-firefox-debuginforedhat-upgrade-firefox-debugsourceredhat-upgrade-thunderbirdredhat-upgrade-thunderbird-debuginforedhat-upgrade-thunderbird-debugsource | Jan 14, 2020 | Jan 8, 2020 | |
| Suse | — | suse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-branding-upstreamsuse-upgrade-mozillafirefox-buildsymbolssuse-upgrade-mozillafirefox-develsuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-othersuse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-other | Jan 11, 2020 | Jan 8, 2020 |
| Ubuntu | ubuntu-upgrade-firefoxubuntu-upgrade-thunderbird | Jan 10, 2020 | Jan 8, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub