You are here: Security Center > Mozilla Foundation Security Advisories > MFSA 2012-47
Mozilla Foundation Security Advisory 2012-47
Title: Improper filtering of javascript in HTML
feed-view
Impact: High
Announced: July 17, 2012
Reporter: Mario Heiderich
Products: Firefox, Thunderbird, SeaMonkey
Fixed in: Firefox 14
Firefox ESR 10.0.6
Thunderbird 14
Thunderbird ESR 10.0.6
SeaMonkey 2.11
Description
Security researcher Mario Heiderich reported that javascript
could be executed in the HTML feed-view using <embed> tag
within the RSS <description>. This problem is due to
<embed> tags not being filtered out during parsing and can
lead to a potential cross-site scripting (XSS) attack. The flaw existed in a
parser utility class and could affect other parts of the browser or add-ons
which rely on that class to sanitize untrusted input.
