When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
History

Sat, 19 Apr 2025 02:00:00 +0000

Type Values Removed Values Added
Title thunderbird: User Interface (UI) Misrepresentation of attachment URL
References
Metrics threat_severity

None

threat_severity

Low


Tue, 15 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Description When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2025-04-15T17:51:38.126Z

Reserved: 2025-04-11T15:27:51.919Z

Link: CVE-2025-3523

cve-icon Vulnrichment

Updated: 2025-04-15T17:51:32.228Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-15T15:16:09.957

Modified: 2025-04-15T18:39:27.967

Link: CVE-2025-3523

cve-icon Redhat

Severity : Low

Publid Date: 2025-04-15T15:06:14Z

Links: CVE-2025-3523 - Bugzilla