Логотип exploitDog
bind:CVE-2023-48114
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-48114

Количество 2

Количество 2

nvd логотип

CVE-2023-48114

около 2 лет назад

SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-qmhv-fq76-x3j5

около 2 лет назад

SmarterTools SmarterMail 16.x 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-48114

SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-qmhv-fq76-x3j5

SmarterTools SmarterMail 16.x 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.

CVSS3: 5.4
0%
Низкий
около 2 лет назад

Уязвимостей на страницу