ID:11122 - Exploit for Input validation error in Mozilla Thunderbird - CVE-2025-1015
Published: February 7, 2025
Mozilla Thunderbird
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input when handling the Address Book URI fields. A remote attacker create and export an address book containing a malicious payload in a field, trick the victim into clicking on the link after importing the address book and a web page inside Thunderbird.