First published: Wed Sep 08 2021(Updated: )
SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus allowing one to inject HTML and/or JavaScript into a page that will then be processed and stored by the application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SmarterTools SmarterMail | >=16.0.6345<16.3.7866 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-40377.
The severity of CVE-2021-40377 is medium.
The affected software is SmarterTools SmarterMail 16.x before build 7866.
CVE-2021-40377 allows injection of HTML and/or JavaScript into a page that can be stored and processed by the application.
To fix CVE-2021-40377, update SmarterTools SmarterMail to build 7866 or later.