7.5
CVSSv3

CVE-2020-12391

Published: 26/05/2020 Updated: 12/07/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that should have been blocked, albeit with a unique opaque origin. This vulnerability affects Firefox < 76.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

USN-4353-1 caused a regression in Firefox ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2020-16 Security Vulnerabilities fixed in Firefox 76 Announced May 5, 2020 Impact critical Products Firefox Fixed in Firefox 76 ...
Documents formed using data: URLs in an object element failed to inherit the CSP of the creating context This allowed the execution of scripts that should have been blocked, albeit with a unique opaque origin ...