#VU25855 Input validation error in Mozilla Firefox and Firefox ESR - CVE-2020-6811
Published: March 10, 2020 / Updated: March 10, 2020
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to execute arbitrary OS commands.
The vulnerability exists due to insufficient validation of user-supplied input copied into buffer via the 'Copy as cURL' feature of Devtools' network tab. A remote attacker can trick the victim into using the 'Copy as cURL' feature to copy malicious data into buffer and later insert them into a terminal window.
Successful exploitation of the vulnerability may result in OS command execution.