CVE Database
/

CVE-2019-11701

Back to search

CVE-2019-11701

Published: Jul 23, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this issue only affects users with an account on the vulnerable service. Other users are unaffected.*. This vulnerability affects Firefox < 67.

VendorProductVersions

Mozilla

Firefox

affected
unspecified - < 67

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now