CVE-2020-6798
Published: Mar 2, 2020
Modified: Aug 4, 2024
Description
If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but is potentially a risk in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.
| Vendor | Product | Versions |
|---|---|---|
Mozilla | Thunderbird | affected unspecified - < 68.5 |
Mozilla | Firefox | affected unspecified - < 73affected unspecified - < ESR68.5 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now