Stored Cross-Site Scripting Vulnerability in HGiga's C&Cm@il Product
CVE-2025-2150
5.4MEDIUM
What is CVE-2025-2150?
The C&Cm@il product by HGiga contains a vulnerability that allows remote attackers to exploit Stored Cross-Site Scripting (XSS). This issue permits unauthorized individuals with minimal privileges to send emails embedded with harmful JavaScript code. When a user opens the email, the malicious script executes in their browser, potentially compromising user data and system security. This vulnerability underscores the need for rigorous email filtering and user awareness to prevent such attacks.
Affected Version(s)
C&Cm@il 0 < 1.0-238
