CVE-2020-15649

Description

Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files picked. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.243

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2020-15649,CVE-2020-15650 are affected in Mozilla Firefox ESR (x64) 68.10.0Windows
Vulnerability CVE-2020-15649,CVE-2020-15650 are affected in Mozilla Firefox ESR 68.10.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 68.0.1Mac
Multiple Vulnerabilities are affected in Firefox ESR for Mac 68.0.1Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234