CVE-2017-7846
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View - Feed
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View - Feed article - Website" or in the standard format of "View - Feed article - default format". This vulnerability affects Thunderbird < 52.5.2.
HIGH · CVSS 8.8
EPSS 0.01283
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0