Impact
Cross‑site scripting occurs in hMailServer’s webmail interface for versions 6.3.2 through 6.3.5 when a user opens a decrypted S/MIME or OpenPGP attachment in a new browser tab. The attachment is served as a blob URL with the media type declared in the message. If that type is text/html, the browser renders it as a document belonging to the webmail’s origin, allowing injected script to read the user’s mailbox, send mail, and modify the account through the REST API. This effectively gives a remote attacker the ability to run code within the victim’s session.
Affected Systems
Progressive Robot Ltd hMailServer versions 6.3.2 to 6.3.5 are affected. The webmail feature is exposed only when the REST API is enabled, which is not enabled by default.
Risk and Exploitability
The vulnerability receives a CVSS score of 8, with no EPSS score available and not listed in CISA KEV. An attacker who can send an encrypted message to a user can exploit this by having the user open the attachment in a new tab, which is a user‑triggered attack. Because the webmail interface is normally protected behind the REST API, the practical exposure depends on the API being enabled and a user accessing a crafted encrypted message. The CVSS score indicates a high likelihood of serious impact if exploited, and the lack of EPSS data suggests limited public exploitation evidence to date.
OpenCVE Enrichment