Lucene search

K
cvelistMitreCVELIST:CVE-2023-48114
HistoryDec 21, 2023 - 12:00 a.m.

CVE-2023-48114

2023-12-2100:00:00
mitre
www.cve.org
6
cve-2023-48114
smartermail
xss
svg
youtube.com

EPSS

0

Percentile

14.0%

SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.

EPSS

0

Percentile

14.0%

Related for CVELIST:CVE-2023-48114