Attacker Value
Unknown
(1 user assessed)
Exploitability
Unknown
(1 user assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
1

CVE-2020-26951

Last updated October 12, 2020
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Add Assessment

2
Technical Analysis

Mozilla recently announced a fix for this vulnerability in Firefox 83. They marked this as Impact: high and provided the following details in their published advisory:

A parsing and event loading mismatch in Firefox’s SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer.

The ability to bypass sanitization sounds like it’s worth Firefox users to patch to version 83.

General Information

Additional Info

Technical Analysis