#VU63875 Path traversal in Mozilla Firefox and Firefox ESR - CVE-2022-31739
Published: May 31, 2022 / Updated: November 9, 2022
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when saving downloaded files on Windows. A remote attacker can use the "%" character in filename to store data outside the intended directory using Windows environment variables, such as %HOMEPATH% or %APPDATA%.
The vulnerability affects Windows installations only.