CVE-2023-48115

SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*

History

04 Jan 2024, 18:52

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
First Time Smartertools smartermail
Smartertools
CPE cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*
CWE CWE-79
References () https://www.smartertools.com/smartermail/release-notes/current - () https://www.smartertools.com/smartermail/release-notes/current - Release Notes
References () https://co3us.gitbook.io/write-ups/stored-dom-xss-in-email-body-of-smartermail - () https://co3us.gitbook.io/write-ups/stored-dom-xss-in-email-body-of-smartermail - Exploit, Third Party Advisory

21 Dec 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-21 15:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-48115

Mitre link : CVE-2023-48115

CVE.ORG link : CVE-2023-48115


JSON object : View

Products Affected

smartertools

  • smartermail
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')