By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within the bounds of the same-origin policy) even after the tab was closed. This vulnerability affects Firefox < 97.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 97.0 |