5
CVSSv2

CVE-2020-6813

Published: 25/03/2020 Updated: 30/03/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an malicious user to inject arbitrary styles, bypassing the intent of the Content Security Policy. This vulnerability affects Firefox < 74.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2020-08 Security Vulnerabilities fixed in Firefox 74 Announced March 10, 2020 Impact high Products Firefox Fixed in Firefox 74 ...
A Content Security Policy bypass has been found in Firefox before 74 When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Content Security Policy ...