CVE-2019-7211: XSS
Published Apr 24, 2019
·Updated
SmarterTools SmarterMail 16.x before build 6995 has stored XSS. JavaScript code could be executed on the application by opening a malicious email or when viewing a malicious file attachment.
Affected Software
1 affected component
SmarterTools SmarterMail>=16.0.6345<16.3.6955
Event History
Apr 24, 2019
CVE Published
via MITRE·02:37 PM
Data Sourced
via MITRE·02:37 PM
Description
Data Sourced
via NVD·03:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-7211?
CVE-2019-7211 is a vulnerability in SmarterTools SmarterMail 16.x before build 6995 that allows for stored XSS attacks.
2
How can JavaScript code be executed in SmarterMail?
JavaScript code can be executed in SmarterMail by opening a malicious email or viewing a malicious file attachment.
3
What is the severity of CVE-2019-7211?
The severity of CVE-2019-7211 is medium with a CVSS score of 6.1.
4
What software is affected by CVE-2019-7211?
SmarterTools SmarterMail 16.x versions before build 6995 are affected by CVE-2019-7211.
5
How can I fix CVE-2019-7211 in SmarterMail?
To fix CVE-2019-7211, update SmarterMail to build 6995 or later.