The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to bypass an HTML Sanitizer. This vulnerability affects Firefox < 86.
Link | Tags |
---|---|
https://www.mozilla.org/security/advisories/mfsa2021-07/ | release notes vendor advisory |
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1528997%2C1683627 | issue tracking vendor advisory |
https://security.gentoo.org/glsa/202104-10 | third party advisory vendor advisory |