← Back to CVE List

CVE-2022-22759

Published: 2022-12-22T20:15Z
Last Modified: 2024-11-21T06:47Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt