Mozilla · Firefox · CVE-2019-11701
**Name of the Vulnerable Software and Affected Versions**
Firefox versions prior to 67
**Description**
The default webcal: protocol handler in Firefox is vulnerable to cross-site scripting (XSS) attacks, which could allow a remote attacker to impact data integrity. This issue only affects users with an account on the vulnerable service, while other users are unaffected.
**Recommendations**
For versions prior to 67, update to version 67 or later to resolve the issue. As a temporary workaround, consider disabling the webcal: protocol handler until a patch is available. Restrict access to the vulnerable service to minimize the risk of exploitation.