Vulnerability CVE-2023-48115


Published: 2023-12-21

Description:
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.

 References:
https://co3us.gitbook.io/write-ups/stored-dom-xss-in-email-body-of-smartermail
https://www.smartertools.com/smartermail/release-notes/current

Copyright 2026, cxsecurity.com

 

Back to Top