#VU66921 Security features bypass in Mozilla Thunderbird - CVE-2022-3034
Published: September 1, 2022 / Updated: October 20, 2022
Mozilla Thunderbird
Mozilla
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to iframe elements in an HTML email force the application to initiate network requests. A remote attacker can use an iframe to confirm that the email was read by the victim and obtain victim's IP address.