Stored XSS Vulnerability in SmarterMail by SmarterTools
CVE-2015-9276
6.1MEDIUM
What is CVE-2015-9276?
SmarterMail, a popular email server software by SmarterTools, is susceptible to a stored Cross-Site Scripting (XSS) vulnerability which allows attackers to inject malicious JavaScript code into email messages. This loophole enables an attacker to execute the injected script when an unsuspecting victim opens or replies to the compromised email. Notably, the vulnerability poses a significant risk as it permits unauthorized password resets without the need for the current password, effectively compromising user accounts. The affected versions are those prior to 13.3.5535, making upgrading essential to safeguard user data.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved