ZeroHour

CVE-2025-3523

CVSS 3.1
6.4 medium
EPSS
<1%p23
Published
()
Modified
Description

When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.

Vendors
mozilla
Products
thunderbird
Weakness
CWE-451
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L

In the news

No ingested article mentions this CVE yet.