CVE-2022-45404: Medium severity thunderbird vulnerability
Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Other sources
Through a series of popup and window.print() calls, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-45404?
CVE-2022-45404 is a vulnerability that allows an attacker to cause a window to go fullscreen without the user seeing the notification prompt, potentially leading to user confusion or spoofing attacks.
Which software versions are affected by CVE-2022-45404?
CVE-2022-45404 affects Firefox ESR versions less than 102.5, Thunderbird versions less than 102.5, and Firefox versions less than 107.
What is the severity of CVE-2022-45404?
CVE-2022-45404 has a severity rating of 6.5, which is considered high.
How can this vulnerability be exploited?
This vulnerability can be exploited through a series of popup and window.print() calls.
Are there any references related to CVE-2022-45404?
Yes, you can find more information about CVE-2022-45404 at the following references: [Reference 1](https://bugzilla.mozilla.org/show_bug.cgi?id=1790815), [Reference 2](https://www.mozilla.org/en-US/security/advisories/mfsa2022-49/), [Reference 3](https://www.mozilla.org/en-US/security/advisories/mfsa2022-47/).