An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>allow-scripts</code> being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
2022-12-22T20:15:25.803
2025-04-16T14:15:21.093
Modified
CVSSv3.1: 6.1 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mozilla | firefox | < 100.0 | Yes |
| Application | mozilla | firefox_esr | < 91.9 | Yes |
| Application | mozilla | thunderbird | < 91.9 | Yes |