CVE-2023-48115

SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:31

Type Values Removed Values Added
References () https://co3us.gitbook.io/write-ups/stored-dom-xss-in-email-body-of-smartermail - Exploit, Third Party Advisory () https://co3us.gitbook.io/write-ups/stored-dom-xss-in-email-body-of-smartermail - Exploit, Third Party Advisory
References () https://www.smartertools.com/smartermail/release-notes/current - Release Notes () https://www.smartertools.com/smartermail/release-notes/current - Release Notes

04 Jan 2024, 18:52

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
First Time Smartertools smartermail
Smartertools
References () https://co3us.gitbook.io/write-ups/stored-dom-xss-in-email-body-of-smartermail - () https://co3us.gitbook.io/write-ups/stored-dom-xss-in-email-body-of-smartermail - Exploit, Third Party Advisory
References () https://www.smartertools.com/smartermail/release-notes/current - () https://www.smartertools.com/smartermail/release-notes/current - Release Notes
Summary
  • (es) SmarterTools SmarterMail 8495 a 8664 antes de 8747 permite DOM XSS almacenado porque se omite un mecanismo de protección XSS cuando messageHTML y messagePlainText se configuran en la misma solicitud.
CWE CWE-79
CPE cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*

21 Dec 2023, 16:15

Type Values Removed Values Added
Summary (en) SmarterTools SmarterMail 16.x 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request. (en) SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.
References
  • () https://www.smartertools.com/smartermail/release-notes/current -

21 Dec 2023, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-21 15:15

Updated : 2024-11-21 08:31


NVD link : CVE-2023-48115

Mitre link : CVE-2023-48115

CVE.ORG link : CVE-2023-48115


JSON object : View

Products Affected

smartertools

  • smartermail
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')