vulnerability
MFSA2021-07 Firefox: Security Vulnerabilities fixed in Firefox 86 (CVE-2021-23974)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
4 | (AV:N/AC:M/Au:N/C:N/I:P/A:N) | Feb 23, 2021 | Feb 24, 2021 | Mar 5, 2021 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Feb 23, 2021
Added
Feb 24, 2021
Modified
Mar 5, 2021
Description
The DOMParser API did not properly process '' elements for escaping. This could be used as an mXSS vector to bypass an HTML Sanitizer. This vulnerability affects Firefox
Solution
mozilla-firefox-upgrade-86_0

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.