By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2020-10-01T18:31:16

Updated: 2024-08-04T13:22:30.687Z

Reserved: 2020-07-10T00:00:00

Link: CVE-2020-15677

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-10-01T19:15:13.830

Modified: 2022-11-16T15:15:40.607

Link: CVE-2020-15677

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-09-22T00:00:00Z

Links: CVE-2020-15677 - Bugzilla