CVE-2019-11720

Source
Severity Medium
Remote Yes
Type Insufficient validation
Description
In Firefox before 68.0, some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) filtering.
Group Package Affected Fixed Severity Status Ticket
AVG-1002 firefox 67.0.4-2 68.0-1 Critical Fixed
Date Advisory Group Package Severity Description
17 Jul 2019 ASA-201907-4 AVG-1002 firefox Critical multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2019-21/#CVE-2019-11720
https://bugzilla.mozilla.org/show_bug.cgi?id=1556230