An incorrect parsing of template could result in Javascript injection in Firefox before 73.0. If a <template> tag was used in a <select%gt; tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result.
An incorrect parsing of template could result in Javascript injection in Firefox before 73.0. If a <template> tag was used in a <select%gt; tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result.
https://www.mozilla.org/en-US/security/advisories/mfsa2020-05/#CVE-2020-6798 https://bugzilla.mozilla.org/show_bug.cgi?id=1602944