CVE-2022-22759 describes a critical vulnerability in Firefox, Thunderbird, and Firefox ESR where a sandboxed iframe, even without script execution permissions, could still execute JavaScript event handlers if an element with such a handler was appended to its document. This allows for arbitrary code execution with a CVSS score of 9.6, indicating a critical severity with network-based attacks and high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high risk score warrants prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 97.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 91.6CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* | ||
< 91.6CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.