PT-2020-14571 · Mozilla · Firefox

Superxx

·

Published

2020-08-10

·

Updated

2021-07-21

·

CVE-2020-15651

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Firefox for iOS versions prior to 28
Description A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension.
Recommendations For versions prior to 28, update to version 28 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-15651

Affected Products

Firefox