Back

MEDIUM

Mozilla: An iframe element in an HTML email could trigger a network request

Published Dec 22, 2022

Description

When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mozilla
Published Dec 22, 2022
Updated Apr 15, 2025
Reserved Aug 29, 2022

CISA Vulnrichment

Updated Apr 15, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Aug 31, 2022
Bugzilla 2123257

ENISA EUVD

Assigner mozilla
Published Dec 22, 2022
Updated Apr 15, 2025

GitHub

No data