First published: Thu Dec 21 2023(Updated: )
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SmarterTools SmarterMail Enterprise | >=16.0.8495<16.0.8747 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48115 has a medium severity level due to the potential for stored DOM XSS attacks.
To fix CVE-2023-48115, upgrade SmarterMail to version 16.0.8747 or later.
CVE-2023-48115 affects SmarterTools SmarterMail versions 8495 through 8664 prior to 8747.
CVE-2023-48115 is categorized as a stored DOM Cross-Site Scripting (XSS) vulnerability.
Attackers exploiting CVE-2023-48115 can execute arbitrary scripts in the context of users viewing affected messages.