If an attacker could control the contents of an iframe...
Critical severity
Unreviewed
Published
Dec 22, 2022
to the GitHub Advisory Database
•
Updated Apr 16, 2025
Description
Published by the National Vulnerability Database
Dec 22, 2022
Published to the GitHub Advisory Database
Dec 22, 2022
Last updated
Apr 16, 2025
If an attacker could control the contents of an iframe sandboxed with
allow-popups
but notallow-scripts
, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.References