Related Vulnerabilities: CVE-2021-38503  

The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame.

Severity High

Remote Yes

Type Sandbox escape

Description

The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame.

AVG-2511 firefox 93.0-1 94.0-1 High Testing

https://www.mozilla.org/security/advisories/mfsa2021-48/
https://bugzilla.mozilla.org/show_bug.cgi?id=1729517