#VU46963 Spoofing attack in Mozilla Firefox and Firefox ESR - CVE-2020-15677
Published: September 23, 2020
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The
vulnerability exists due to way Firefox displays name of the data
origin when downloading files. A remote attacker can spoof origin of the
downloaded file and display the name of the intermediate website instead of the original source name.
Successful exploitation of this
vulnerability may allow a remote attacker to perform a phishing attack but requires that the spoofed website has an open redirect vulnerability.