CVE-2019-11744 is a cross-site scripting (XSS) vulnerability affecting Mozilla Firefox and Thunderbird versions prior to 69 and 68.1 respectively. It arises from specific HTML elements like <title> and <textarea> incorrectly parsing literal closing tags, allowing subsequent content to be interpreted outside the element. With a CVSS score of 6.1 (Medium), this vulnerability requires user interaction (UI:R) and could lead to information disclosure and data integrity issues (C:L, I:L). While no public exploit code or Metasploit modules are available, and it is not listed in CISA's KEV catalog, the vulnerability has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 60.9CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 69.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
>= 68.0, < 68.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 60.9CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
>= 68.0, < 68.1CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.