CVE-2020-15648

CVSS v3.1 6.5 (Medium)
65% Progress
CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.13 % (48th)
0.13% Progress
Affected Products 2
Advisories 6

Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.

Weaknesses
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2020-08-10 18:15:12
(4 years ago)
Updated Date
2020-08-12 16:27:43
(4 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 78.0.2 version cpe:2.3:a:mozilla:firefox < 78.0.2
  Mozilla Thunderbird prior 78.0 version cpe:2.3:a:mozilla:thunderbird < 78.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...