CVE-2019-11763: XSS
A flaw was found in Mozilla Firefox and Thunderbird where null bytes were incorrectly parsed in HTML entities. This could lead to HTML comments being treated as code which could lead to XSS in a web application or HTML entities being masked from filters.
Other sources
Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of entities to mask the actual characters of interest from filters.
— Mozilla
Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters, enabling the use of entities to mask the actual characters of interest from filters.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-11763?
CVE-2019-11763 is a vulnerability found in Mozilla Firefox and Thunderbird that allows for XSS attacks.
How severe is CVE-2019-11763?
CVE-2019-11763 has a severity rating of medium.
Which software is affected by CVE-2019-11763?
Mozilla Firefox and Thunderbird versions up to 68.2.0-4.el6_10, 68.2.0-2.el6_10, 68.2.0-1.el7_7, 68.2.0-1.el8_0, and 68.2.0-2.el8_0 are affected by CVE-2019-11763.
How can I fix CVE-2019-11763?
To fix CVE-2019-11763, update Mozilla Firefox and Thunderbird to version 68.2 or later.
Where can I find more information about CVE-2019-11763?
You can find more information about CVE-2019-11763 on the Mozilla website and Bugzilla.