CVE Published: 09/07/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: mozilla |
Vendor: Mozilla |
Product: Firefox Status : PUBLISHED
CVE-2020-12412 Description
By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with the https:// scheme, a blocked port number such as \'1\', and without a lock icon) while controlling the page contents. This vulnerability affects Firefox < 70.