Medium severity5.5NVD Advisory· Published Aug 10, 2020· Updated Jun 17, 2026
CVE-2020-15649
CVE-2020-15649
Description
Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files picked. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*range: <68.11
- (no CPE)range: <68.11
- (no CPE)range: unspecified
- Range: <68.11
Patches
Vulnerability mechanics
References
2- bugzilla.mozilla.org/buglist.cginvdIssue TrackingVendor Advisory
- www.mozilla.org/security/advisories/mfsa2020-31/nvdVendor Advisory
News mentions
0No linked articles in our index yet.