#VU66920 Security features bypass in Mozilla Thunderbird - CVE-2022-3032
Published: September 1, 2022 / Updated: October 20, 2022
Mozilla Thunderbird
Mozilla
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists doe to incorrect processing of HTML emails with an iframe</code> element that uses a <code>srcdoc attribute to define the inner HTML document. A remote attacker can trick the victim to open a specially crafted email message and bypass blocking of remote objects specified in the nested document, for example images or videos.