3.3
CVSSv3

CVE-2020-12394

Published: 26/05/2020 Updated: 26/04/2022
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A logic flaw in our location bar implementation could have allowed a local malicious user to spoof the current location by selecting a different origin and removing focus from the input element. This vulnerability affects Firefox < 76.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

USN-4353-1 caused a regression in Firefox ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2020-16 Security Vulnerabilities fixed in Firefox 76 Announced May 5, 2020 Impact critical Products Firefox Fixed in Firefox 76 ...
A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and removing focus from the input element ...