CVE-2020-15665
Last modified
CVE-2020-15665 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. This could have resulted in an incorrect URL being shown when used in conjunction with other unexpected browser behaviors. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. This could have resulted in an incorrect URL being shown when used in conjunction with other unexpected browser behaviors. This vulnerability affects Firefox < 80.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 80.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1651636Exploit, Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-36/Release Notes, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1651636Exploit, Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-36/Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-15665?
How severe is CVE-2020-15665?
How do I fix CVE-2020-15665?
Are you affected by CVE-2020-15665?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
