CVE Database
/

CVE-2020-26965

Back to search

CVE-2020-26965

Published: Dec 9, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remembers user input, a user typed their password and used that feature, the type of the password field was changed, resulting in a keyboard layout change and the possibility for the software keyboard to remember the typed password. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

VendorProductVersions

Mozilla

Firefox

affected
< 83

Mozilla

Firefox ESR

affected
< 78.5

Mozilla

Thunderbird

affected
< 78.5

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now