CVE-2017-7846 — Injection in Mozilla Thunderbird
Severity
8.8HIGHNVD
OSV5.3
EPSS
1.3%
top 20.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 14
Description
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages7 packages
Also affects: Debian Linux 7.0, 8.0, 9.0, Enterprise Linux 7.4, 7.5
🔴Vulnerability Details
4GHSA▶
GHSA-2529-rwp4-75f6: It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e↗2022-05-14
OSV▶
CVE-2017-7846: It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e↗2018-06-11
CVEList▶
CVE-2017-7846: It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e↗2018-06-11