CVE-2022-45408: XSS
Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-45408?
CVE-2022-45408 is a vulnerability that allows an attacker to cause a window to go fullscreen without the user seeing the notification prompt, potentially leading to user confusion or spoofing attacks.
Which software is affected by CVE-2022-45408?
This vulnerability affects Firefox ESR versions earlier than 102.5, Thunderbird versions earlier than 102.5, and Firefox versions earlier than 107.
How can an attacker exploit CVE-2022-45408?
By using a series of popups that reuse windowName, an attacker can trigger the window to go fullscreen without the user's awareness.
What is the severity of CVE-2022-45408?
CVE-2022-45408 has a severity value of 6.5, which is considered high.
How can I fix CVE-2022-45408?
To fix CVE-2022-45408, you should update your Firefox ESR, Thunderbird, and Firefox installations to versions 102.5 and 107, respectively, or later.