#VU24054 Code Injection in Mozilla Firefox and Firefox ESR - CVE-2019-17016
Published: January 7, 2020 / Updated: January 8, 2020
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper input validation when pasting a tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration.