A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
2024-10-01T16:15:10.847
2025-03-18T16:15:26.400
Modified
CVSSv3.1: 6.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | firefox | < 131.0 | Yes |
Application | mozilla | firefox_esr | < 128.3.0 | Yes |
Application | mozilla | thunderbird | < 128.3 | Yes |
Application | mozilla | thunderbird | 129.0 | Yes |
Application | mozilla | thunderbird | 129.0 | Yes |
Application | mozilla | thunderbird | 129.0 | Yes |
Application | mozilla | thunderbird | 129.0 | Yes |
Application | mozilla | thunderbird | 129.0 | Yes |
Application | mozilla | thunderbird | 129.0 | Yes |