Cross-Site Scripting Flaw in SmarterMail Software from SmarterTools
CVE-2026-104083

5.3MEDIUM

Key Information:

Vendor
CVE Published:
9 October 2026

What is CVE-2026-104083?

SmarterMail prior to build 9777 is vulnerable to a stored mutation cross-site scripting attack. This flaw allows attackers to inject executable scripts by embedding malicious payloads within a element in MathML foreign content. Although the custom HTML sanitizer recognizes this as inert CDATA text, browsers interpret it as active markup during rendering. By crafting a calendar (iCal) message that includes a payload, attackers can trigger automatic script execution in the webmail session of the user upon opening the message, leading to unauthorized data access and potential exploitation of the Content-Security-Policy's leniency.

Affected Version(s)

Smartermail 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

evan
.