Related Vulnerabilities: CVE-2020-15676  

Firefox before 81.0 sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a content-editable element.

Severity Medium

Remote No

Type Cross-site scripting

Description

Firefox before 81.0 sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a content-editable element.

AVG-1235 firefox 80.0.1-1 81.0-1 High Fixed

https://www.mozilla.org/en-US/security/advisories/mfsa2020-42/#CVE-2020-15676
https://bugzilla.mozilla.org/show_bug.cgi?id=1646140