CVE-2022-38473 | Mozilla Thunderbird up to 102.1 XSLT Document cross-domain policy (Bug 1771685 / EUVD-2022-41056)
A vulnerability identified as critical has been detected in Mozilla Thunderbird up to 102.1. Affected is an unknown function of the component XSLT Document Handler. The manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is listed as CVE-2022-38473. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.