This bug only affects Thunderbird for Windows. Other o...">Command injection - vulnerability database | Vulners.comThis bug only affects Thunderbird for Windows. Other o...">This bug only affects Thunderbird for Windows. Other o...">This bug only affects Thunderbird for Windows. Other o...">
Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-22744
HistoryDec 22, 2022 - 8:15 p.m.

Command injection

2022-12-2220:15:00
PRIOn knowledge base
www.prio-n.com
5
command injection
curl command
devtools
powershell
thunderbird
windows
vulnerability
firefox esr
nvd

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.2%

The constructed curl command from the “Copy as curl” feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>This bug only affects Thunderbird for Windows. Other operating systems are unaffected.. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CPENameOperatorVersion
firefoxlt96.0
firefox_esrlt91.5
thunderbirdlt91.5