#VU33035 Cross-site scripting in Firefox ESR - CVE-2019-11715

 

#VU33035 Cross-site scripting in Firefox ESR - CVE-2019-11715

Published: July 23, 2019 / Updated: August 3, 2020


Vulnerability identifier: #VU33035
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-11715
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Firefox ESR
Software vendor:
Mozilla

Description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.


Remediation

Install update from vendor's website.

External links