SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-15676

Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element.

MEDIUM 6.1EPSS 1.59%

Does this matter?

Lower severity and a low EPSS score (1.59%). Track it; it rarely justifies an emergency change on its own.

Description

Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.59% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
mozilla/firefox · mozilla/firefox esr · mozilla/thunderbird · debian/debian linux · opensuse/leap
Source
security@mozilla.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.