Security Advisory
CVE-2020-26951
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
A parsing and event loading mismatch in Firefoxs SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.