CVE-2020-15649

MEDIUM

Mozilla Firefox Esr < 68.11 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files picked. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.

References (2)

Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1475835%2C1652364

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 47.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-434
Status published
Products (1)
mozilla/firefox_esr < 68.11
Published Aug 10, 2020
Tracked Since Feb 18, 2026