Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23026
HistoryApr 10, 2020 - 12:12 a.m.

Cross-Site Scripting (XSS)

2020-04-1000:12:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

EPSS

0.018

Percentile

88.2%

thunderbird is vulnerable to cross-site scripting. Two flaws were found in the way Thunderbird displayed blocked popup windows. If a user can be convinced to open a blocked popup, it is possible to read arbitrary local files, or conduct an XSS attack against the user.

References