Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37147
HistorySep 19, 2022 - 1:00 p.m.

Unsecured File

2022-09-1913:00:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
thunderbird
vulnerability
unsecured
html email
iframe element
srcdoc attribute
remote objects
malicious files
system
software

0.001 Low

EPSS

Percentile

49.1%

thunderbird allows unsecured files. The vulnerability exists due to an issue of when receiving an HTML email that contained an iframe element, which used a srcdoc attribute to define the internal HTML document, remote objects specified in the nested document (for example, images or videos), were not blocked allowing an attacker to load maliciously crafted files into the system.