CVE-2020-15664

CVSS v3.1 6.5 (Medium)
65% Progress
CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.29 % (70th)
0.29% Progress
Affected Products 3
Advisories 33

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.

Weaknesses
CWE-863
Incorrect Authorization
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2020-10-01 19:15:13
(4 years ago)
Updated Date
2020-10-13 14:08:16
(3 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox For prior 80.0 version cpe:2.3:a:mozilla:firefox::*:*:*:*:- < 80.0
  Mozilla Firefox prior 80.0 version cpe:2.3:a:mozilla:firefox::*:*:*:android < 80.0
  Mozilla Firefox Esr prior 68.12 version cpe:2.3:a:mozilla:firefox_esr < 68.12
  Mozilla Firefox Esr from 78.0 version and prior 78.2 version cpe:2.3:a:mozilla:firefox_esr >= 78.0 < 78.2
  Mozilla Thunderbird prior 68.12 version cpe:2.3:a:mozilla:thunderbird < 68.12
  Mozilla Thunderbird from 78.0 version and prior 78.2 version cpe:2.3:a:mozilla:thunderbird >= 78.0 < 78.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...