CVE-2020-15649
published 2020-08-10CVE-2020-15649: Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.72%
50.2th percentile
Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files picked. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox_esr | < 68.11 | 68.11 |
| mozilla | firefox_esr | >= unspecified < 68.11 | 68.11 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Exfiltrating local files through malicious file picker application
vendor_redhat·2020-07-28·CVSS 5.5
CVE-2020-15649 [MEDIUM] CWE-552 Mozilla: Exfiltrating local files through malicious file picker application
Mozilla: Exfiltrating local files through malicious file picker application
Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files picked. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.
Statement: This issue only affected Firefox for Android. Other operating systems are unaffected.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: firefox (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2020-15649: firefox - Given an installed malicious file picker application, an attacker was able to st...
vendor_debian·2020·CVSS 5.5
CVE-2020-15649 [MEDIUM] CVE-2020-15649: firefox - Given an installed malicious file picker application, an attacker was able to st...
Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files picked. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2020-31: CVE-2020-15649
vendor_mozilla·CVSS 5.5
CVE-2020-15649 [MEDIUM] Mozilla Foundation Security Advisory 2020-31: CVE-2020-15649
Mozilla Foundation Security Advisory 2020-31
CVE: CVE-2020-15649
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 68.11
GHSA
GHSA-wg7m-wv28-cvcr: Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actual
ghsa_unreviewed·2022-05-24
CVE-2020-15649 [MEDIUM] GHSA-wg7m-wv28-cvcr: Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actual
Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files picked. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.
No detection rules found.
No public exploits indexed.
2020-08-10
Published