VDB
CISA-2025-3033
CISA-2025-3033
PUBLISHED
CVSS 7.7 HIGH
Reported by mozilla · Published April 1, 2025
After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 137 and Thunderbird < 137.
Risk Scores
CVSS 3.1
7.7
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | unspecified |
| Mozilla | Thunderbird | unspecified |
| Mozilla | Firefox | unspecified, unspecified |
| Mozilla | Thunderbird | *, * |
Timeline
- Apr 1, 2025 CVE Published
- Apr 1, 2025 CVE Updated