Related Vulnerabilities: CVE-2021-43528  

Thunderbird before version 91.4.0 unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities.

Severity Low

Remote Yes

Type Arbitrary code execution

Description

Thunderbird before version 91.4.0 unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities.

AVG-2608 thunderbird 91.3.2-2 High Vulnerable

https://www.mozilla.org/security/advisories/mfsa2021-54/
https://bugzilla.mozilla.org/show_bug.cgi?id=1742579