CVE-2023-48115

SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*

History

04 Jan 2024, 18:52

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*
Summary
  • (es) SmarterTools SmarterMail 8495 a 8664 antes de 8747 permite DOM XSS almacenado porque se omite un mecanismo de protección XSS cuando messageHTML y messagePlainText se configuran en la misma solicitud.
References () https://co3us.gitbook.io/write-ups/stored-dom-xss-in-email-body-of-smartermail - () https://co3us.gitbook.io/write-ups/stored-dom-xss-in-email-body-of-smartermail - Exploit, Third Party Advisory
References () https://www.smartertools.com/smartermail/release-notes/current - () https://www.smartertools.com/smartermail/release-notes/current - Release Notes
CWE CWE-79
First Time Smartertools
Smartertools smartermail

21 Dec 2023, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-21 15:15

Updated : 2024-01-04 18:52


NVD link : CVE-2023-48115

Mitre link : CVE-2023-48115

CVE.ORG link : CVE-2023-48115


JSON object : View

Products Affected

smartertools

  • smartermail
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')