CVE-2022-28284

HIGH

Firefox < 99.0 - Cross-Site Scripting via SVG Use Element

Title source: llm
STIX 2.1

Description

SVG's <code>&lt;use&gt;</code> element could have been used to load unexpected content that could have executed script in certain circumstances. While the specification seems to allow this, other browsers do not, and web developers relied on this property for script security so gecko's implementation was aligned with theirs. This vulnerability affects Firefox < 99.

References (2)

Core 2
Core References
Issue Tracking, Permissions Required, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1754522

Scores

CVSS v3 8.8
EPSS 0.0055
EPSS Percentile 41.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-116
Status published
Products (1)
mozilla/firefox < 99.0
Published Dec 22, 2022
Tracked Since Feb 18, 2026