Impact
A remote attacker can send a crafted HTML email containing a spoofed vCard control. When a user clicks that control, Evolution incorrectly assigns an attacker‑controlled JavaScript URL to an iframe in the mail view, allowing the attacker to run arbitrary JavaScript as if it were part of the trusted mail content. The vulnerability bypasses the intended restrictions that prevent script execution in email bodies, exposing the victim to potential code execution, data exfiltration, or other in‑mail attacks.
Affected Systems
The flaw is present in the Evolution mail client distributed with Red Hat Enterprise Linux 6, 7, 8, and 9. No specific application version numbers are listed, indicating that all versions of Evolution bundled with these operating systems are affected.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, so publicly documented exploits are not yet reported. Exploitation requires that the victim opens the crafted email and clicks the spoofed control, suggesting a social‑engineering vector. Because the flaw is not remotely exploitable prior to delivery, the risk is limited to environments where users routinely open emails containing JavaScript or vCard controls. Immediate attention is advisable to prevent potential in‑mail code execution.
OpenCVE Enrichment