Cross-site scripting in Firefox ESR - CVE-2019-11715

 

Cross-site scripting in Firefox ESR - CVE-2019-11715

Published: July 23, 2019 / Updated: August 3, 2020


Vulnerability identifier: #VU33035
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-11715
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Mozilla
Affected software:
Firefox ESR

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.


How to mitigate CVE-2019-11715

Install update from vendor's website.

Sources