PT-2020-6727 · Mozilla · Firefox For Ios

Muneaki Nishimura

·

Published

2020-07-28

·

Updated

2021-01-09

·

CVE-2020-15661

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox for iOS versions prior to 28
Description The issue is related to insufficient protection of registration data, allowing a rogue webpage to override the injected WKUserScript used by the logins autofill. This could result in leaking a password for the current domain. A remote attacker may exploit this to gain access to user passwords for the current domain.
Recommendations For Firefox for iOS versions prior to 28, update to version 28 or later to resolve the issue.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05803
CVE-2020-15661

Affected Products

Firefox For Ios