#VU70147 Input validation error in Mozilla Firefox and Firefox ESR - CVE-2022-46874
Published: December 13, 2022
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to perform a spoofing attack.
The vulnerability exists due to insufficient validation of long filenames during drag and drop actions, which causes filename truncation to a potentially malicious extension. A remote attacker can trick the victim to download a file with a long filename, which can be automatically truncated by the browser into an executable file.