6.5
CVSSv3

CVE-2020-15682

Published: 22/10/2020 Updated: 30/10/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A spoofing issue has been found in Firefox prior to 82.0 where, when a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack. This was fixed by changing external protocol prompts to be tab-modal while also ensuring they could not be incorrectly associated with a different origin.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Mozilla Foundation Security Advisory 2020-45 Security Vulnerabilities fixed in Firefox 82 Announced October 20, 2020 Impact high Products Firefox Fixed in Firefox 82 ...
A spoofing issue has been found in Firefox before 820 where, when a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack This was fixed by changing ext ...