CVE-2022-45415: Malicious File Upload
Published Nov 15, 2022
·Updated
When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran.
Affected Software
2 affected componentsFixes available
Mozilla Firefox<107
107
Mozilla Firefox<107.0
Event History
Nov 15, 2022
CVE Published
12:00 AM
Dec 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is CVE-2022-45415?
CVE-2022-45415 is a vulnerability in Mozilla Firefox that allows malicious files to be saved with incorrect extensions, potentially leading to system compromise.
2
How does CVE-2022-45415 affect Mozilla Firefox?
CVE-2022-45415 affects Mozilla Firefox versions up to and excluding version 107.
3
What is the severity of CVE-2022-45415?
CVE-2022-45415 has a severity level of medium.
4
How can CVE-2022-45415 be exploited?
CVE-2022-45415 can be exploited when downloading an HTML file with a maliciously formatted title.
5
Is there a fix for CVE-2022-45415?
Yes, Mozilla has released a remedy for CVE-2022-45415 in Firefox version 107.