Stored XSS Vulnerability in SmarterMail by SmarterTools
CVE-2015-9276
6.1MEDIUM
What is CVE-2015-9276?
SmarterMail, a popular email server software by SmarterTools, is susceptible to a stored Cross-Site Scripting (XSS) vulnerability which allows attackers to inject malicious JavaScript code into email messages. This loophole enables an attacker to execute the injected script when an unsuspecting victim opens or replies to the compromised email. Notably, the vulnerability poses a significant risk as it permits unauthorized password resets without the need for the current password, effectively compromising user accounts. The affected versions are those prior to 13.3.5535, making upgrading essential to safeguard user data.