When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.
2022-12-22T20:15:35.617
2025-04-15T17:15:35.397
Modified
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | firefox | < 103.0 | Yes |
Application | mozilla | firefox_esr | < 102.1 | Yes |
Application | mozilla | thunderbird | < 102.1 | Yes |
Application | mozilla | firefox_esr | < 91.12 | Yes |
Application | mozilla | thunderbird | < 91.12 | Yes |