Related Vulnerabilities: CVE-2020-6798  

An incorrect parsing of template could result in Javascript injection in Firefox before 73.0. If a <template> tag was used in a <select%gt; tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result.

Severity Medium

Remote Yes

Type Cross-site scripting

Description

An incorrect parsing of template could result in Javascript injection in Firefox before 73.0. If a <template> tag was used in a <select%gt; tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result.

AVG-1096 firefox 72.0.2-1 73.0-1 Critical Fixed

https://www.mozilla.org/en-US/security/advisories/mfsa2020-05/#CVE-2020-6798
https://bugzilla.mozilla.org/show_bug.cgi?id=1602944