PT-2020-19229 · Mozilla+5 · Firefox+7

Terjanq

·

Published

2020-02-11

·

Updated

2024-12-12

·

CVE-2020-6798

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 68.5 Firefox versions prior to 73 Firefox ESR versions prior to 68.5
Description The issue arises when a template tag is used in a select tag, causing the parser to be confused and potentially allowing JavaScript parsing and execution where it should not be allowed. This could lead to a cross-site scripting issue for sites relying on correct browser behavior. The risk is more significant in browser or browser-like contexts, rather than in email clients like Thunderbird, where scripting is disabled during mail reading.
Recommendations For Thunderbird versions prior to 68.5, update to version 68.5 or later. For Firefox versions prior to 73, update to version 73 or later. For Firefox ESR versions prior to 68.5, update to version 68.5 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1182
ALT-PU-2020-1186
ALT-PU-2020-1237
ALT-PU-2020-1399
ALT-PU-2020-1515
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2020-3442
ALT-PU-2021-1368
ALT-PU-2021-3368
CESA-2020_0512
CESA-2020_0520
CESA-2020_0521
CESA-2020_0574
CESA-2020_0576
CESA-2020_0577
CVE-2020-6798
DLA-2102-1
DLA-2104-1
DSA-4620-1
DSA-4625-1
MGASA-2020-0090
MGASA-2020-0091
OPENSUSE-SU-2020:0230-1
OPENSUSE-SU-2020:0231-1
OPENSUSE-SU-2020_0230-1
OPENSUSE-SU-2020_0231-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
RHSA-2020:0512
RHSA-2020:0519
RHSA-2020:0520
RHSA-2020:0521
RHSA-2020:0565
RHSA-2020:0574
RHSA-2020:0576
RHSA-2020:0577
RHSA-2020_0512
RHSA-2020_0520
RHSA-2020_0521
RHSA-2020_0574
RHSA-2020_0576
RHSA-2020_0577
SUSE-SU-2020:0383-1
SUSE-SU-2020:0384-1
SUSE-SU-2020:0385-1
SUSE-SU-2020:14290-1
USN-4278-1
USN-4278-2
USN-4278-3
USN-4328-1
USN-4335-1

Affected Products

Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird
Ubuntu