CVE-2020-15660

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
20/07/2021
Last modified:
22/02/2022

Description

Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:geckodriver:*:*:*:*:*:*:*:* 0.27.0 (excluding)