Impact
The flaw is a client‑side cross‑site scripting issue in the contacts module of Cypht. It enables an attacker to embed malicious script tags in the FROM email header. When a user opens a crafted message and triggers the Add Local Contacts function, the script runs in the victim’s browser, potentially allowing credential theft, defacement, or other browser‑based attacks.
Affected Systems
All Cypht installations running a version earlier than 2.12.2 are impacted. The product is the Cypht webmail application managed by cypht‑org. Users should verify their local version and apply the 2.12.2 release that contains the fix.
Risk and Exploitability
With a CVSS score of 5.1, the vulnerability poses moderate risk. The EPSS score is currently unavailable and the issue is not listed in the CISA KEV catalog, indicating no evidence of widespread exploitation. Attackers can exploit the weakness by sending a forged email whose FROM header contains malicious payloads; the victim must open the message and access the vulnerable function. No privileged access or network resources beyond email delivery are required, so the potential reach is wide among users who interact with the contacts feature.
OpenCVE Enrichment