CyberSec.Space Logo
CVEブラウザに戻る

CVE-2023-48114

MEDIUM
5.4
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2023-12-21
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.

Affected Platforms (CPE)

📦
Smartertools

Smartermail

>= 16.0.8495 and < 16.0.8747

References & Advisories

関連する脆弱性情報