CVE-2020-15661: Medium severity firefox vulnerability
Published Jul 28, 2020
·Updated
A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain.
Affected Software
3 affected components
Mozilla Firefox Iphone Os<28.0
All of the following
Mozilla Firefox=28
Apple iOS
Event History
Jul 28, 2020
CVE Published
12:00 AM
Aug 10, 2020
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2020-15661?
CVE-2020-15661 is considered a moderate severity vulnerability that can lead to password leakage.
2
How do I fix CVE-2020-15661?
To mitigate CVE-2020-15661, users should update to the latest version of Mozilla Firefox beyond version 28.
3
What systems are affected by CVE-2020-15661?
CVE-2020-15661 affects Mozilla Firefox versions up to 28.0 and certain versions on iOS.
4
What could happen if CVE-2020-15661 is exploited?
If exploited, CVE-2020-15661 could result in a rogue webpage leaking passwords used for autofill logins.
5
Who reported CVE-2020-15661?
CVE-2020-15661 was identified and reported by Mozilla in their security advisory.