CVE-2020-6810
Last modified
CVE-2020-6810 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode. Combined with spoofing the browser chrome, this could have led to confusing the user about the current origin of the page and credential theft or other attacks. EPSS estimates a 0.97% chance of exploitation in the next 30 days.
Description
After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode. Combined with spoofing the browser chrome, this could have led to confusing the user about the current origin of the page and credential theft or other attacks. This vulnerability affects Firefox < 74.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 74.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1432856Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-08/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1432856Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-08/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-6810?
How severe is CVE-2020-6810?
How do I fix CVE-2020-6810?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-6804A reflected XSS vulnerability exists within the gateway, all…6.1
- CVE-2020-6805When removing data about an origin whose tab was recently cl…8.8
- CVE-2020-6806By carefully crafting promise resolutions, it was possible t…8.8
- CVE-2020-6807When a device was changed while a stream was about to be des…8.8
- CVE-2020-6808When a JavaScript URL (javascript:) is evaluated and the res…6.5
- CVE-2020-6809When a Web Extension had the all-urls permission and made a …7.5
- CVE-2020-6811The 'Copy as cURL' feature of Devtools' network tab did not …8.8
- CVE-2020-6812The first time AirPods are connected to an iPhone, they beco…5.3
- CVE-2020-6813When protecting CSS blocks with the nonce feature of Content…5.3
- CVE-2020-6814Mozilla developers reported memory safety bugs present in Fi…9.8
- CVE-2020-6815Mozilla developers reported memory safety and script safety …9.8
- CVE-2020-6816In Mozilla Bleach before 3.12, a mutation XSS in bleach.clea…6.1
Are you affected by CVE-2020-6810?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
