Stored XSS Vulnerability in beefree.io SDK's Email Builder Functionality
CVE-2025-12518
5.3MEDIUM
What is CVE-2025-12518?
The beefree.io SDK is susceptible to a Stored XSS vulnerability within the email builder functionality. This flaw allows an attacker to inject arbitrary HTML and JavaScript code through the Social Media icon URL parameter. When the email template is previewed, this malicious content can be rendered and executed. Due to beefree's Content Security Policy, not all injected payloads will be successful, but the potential for exploitation remains a significant security concern. The vulnerability has been addressed in version 3.47.0.
Affected Version(s)
Befree SDK 0 < 3.47.0
