Описание
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
Ссылки
- Patch
- Issue TrackingVendor Advisory
- Issue TrackingPatch
- Mailing ListPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.13 (включая)
cpe:2.3:a:postorius_project:postorius:*:*:*:*:*:*:*:*
EPSS
Процентиль: 15%
0.00237
Низкий
7.2 High
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 7.2
ubuntu
3 месяца назад
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
CVSS3: 7.2
debian
3 месяца назад
Postorius through 1.3.13 does not escape HTML in the message subject w ...
EPSS
Процентиль: 15%
0.00237
Низкий
7.2 High
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79