Total vulnerabilities in the database
In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Software | From | Fixed in |
---|---|---|
mozilla / firefox | - | 83.0 |
mozilla / firefox_esr | - | 78.5 |
mozilla / thunderbird | - | 78.5 |