Cross-Site Scripting Vulnerability in META-INF Kft. Email This Issue Product
CVE-2024-42912

5.4MEDIUM

Key Information:

Vendor
CVE Published:
16 July 2025

What is CVE-2024-42912?

A cross-site scripting (XSS) vulnerability exists in the Email This Issue product by META-INF Kft. Versions prior to 9.13.0-GA are susceptible to this flaw, allowing attackers to inject malicious scripts through the recipient field of an email message. This makes it possible for an attacker to execute arbitrary web scripts or HTML in the context of the user's browser, potentially leading to data theft or user impersonation. Organizations are urged to update to the latest version to mitigate security risks.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.