Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-26384
HistoryDec 22, 2022 - 8:15 p.m.

Code injection

2022-12-2220:15:00
PRIOn knowledge base
www.prio-n.com
7
code injection
iframe sandbox
firefox
thunderbird
vulnerability
javascript execution

8.5 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.8%

If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

CPENameOperatorVersion
firefoxlt98.0
firefox_esrlt91.7
thunderbirdlt91.7