CVE-2020-15648
Description
Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.
Risk Information
Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.316
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities affected in Mozilla Thunderbird (78.0) | Windows |
| Multiple vulnerabilities affected in Mozilla Thunderbird (x64) (78.0) | Windows |
| Vulnerability CVE-2020-15648 are affected in Mozilla Firefox 78.0.1 | Windows |
| Vulnerability CVE-2020-15648 are affected in Mozilla Thunderbird 68.12 | Windows |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.14.0) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.13.0) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.9.0) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.9.1) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.12.0) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.11.0) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.0.1) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.2.0) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.2.1) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.2.2) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.3.0) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.3.1) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.3.2) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.4.0) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.4.3) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.5.0) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.5.1) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.6.0) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.6.1) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.7.0) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.7.1) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.8.0) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Thunderbird For Mac (78.8.1) | Mac |
| Vulnerabilities CVE-2020-15648 are affected in Mozilla Firefox for Mac 78.0.1 | Mac |
| Vulnerabilities CVE-2020-15648 are affected in Mozilla Thunderbird for Mac 68.12 | Mac |
| (RHSA-2020:3557) firefox security update firefox-78.2.0-2.el8_2.x86_64.rpm | Linux |
| (RHSA-2020:3557) firefox security update firefox-debugsource-78.2.0-2.el8_2.x86_64.rpm | Linux |
| (CESA-2020:3557) firefox security update firefox-78.2.0-2.el8_2.x86_64.rpm | Linux |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-321303 | Mozilla Thunderbird (78.14.0) |
| PATCH-321305 | Mozilla Thunderbird (x64) (78.14.0) |
| PATCH-343015 | Mozilla Firefox (132.0.2) |
| PATCH-315938 | Mozilla Thunderbird (68.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611353 | Mozilla Thunderbird For Mac (128.12.0) |
| PATCH-611870 | Mozilla Firefox For Mac (142.0.1) |
| PATCH-611807 | Mozilla Thunderbird For Mac (142.0) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234