#VU48463 Permissions, Privileges, and Access Controls in Mozilla Firefox and Firefox ESR - CVE-2020-26958
Published: November 17, 2020
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due Firefox does not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. A remote attacker can exploit this behavior to perform a cross-site script inclusion vulnerability or bypass implemented Content Security Policy restrictions.