Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qmhv-fq76-x3j5

Опубликовано: 21 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

SmarterTools SmarterMail 16.x 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.

SmarterTools SmarterMail 16.x 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.

EPSS

Процентиль: 38%
0.00169
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 2 лет назад

SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.

EPSS

Процентиль: 38%
0.00169
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79