Misleading Hover Text Vulnerability in Mozilla Thunderbird
CVE-2025-3523

6.4MEDIUM

Key Information:

Vendor
Mozilla
Vendor
CVE Published:
15 April 2025

Summary

A vulnerability in Mozilla Thunderbird allows for a misleading hover text when users view email attachments containing multiple external links. The issue arises from the X-Mozilla-External-Attachment-URL header, which displays only the last link while correctly redirecting on click. This discrepancy could deceive users, leading them to unknowingly download content from untrusted sources, posing significant risks to personal data security.

Affected Version(s)

Thunderbird < 137.0.2

Thunderbird < 128.9.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dario Weißer
.