SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-21T00:00:00

Updated: 2024-08-02T21:23:38.991Z

Reserved: 2023-11-13T00:00:00

Link: CVE-2023-48115

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-12-21T15:15:09.637

Modified: 2024-01-04T18:52:28.027

Link: CVE-2023-48115

cve-icon Redhat

No data.