CVE-2020-15661 PUBLISHED CVSS 6.5 MEDIUM

A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. This vulnerability affects Firefox for iOS < 28.

EPSS 0.21% · 43.6th percentile

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.21%
43.6th percentile

Affected Products

VendorProductVersions
mozillafirefox0
MozillaFirefox for iOSunspecified

Timeline

References

Open in Interactive Console →