#VU32903 Input validation error in Mozilla Firefox and Firefox ESR - CVE-2020-15658
Published: July 29, 2020
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to insufficient validation of special characters during file download,
which led to an attacker being able to cut off the file ending at an
earlier position, leading to a different file type being downloaded than
shown in the dialog. A remote attacker can override file type when saving data to disk.