Cross-Site Scripting Flaw in SmarterMail Software from SmarterTools
CVE-2026-104083
5.3MEDIUM
What is CVE-2026-104083?
SmarterMail prior to build 9777 is vulnerable to a stored mutation cross-site scripting attack. This flaw allows attackers to inject executable scripts by embedding malicious payloads within a element in MathML foreign content. Although the custom HTML sanitizer recognizes this as inert CDATA text, browsers interpret it as active markup during rendering. By crafting a calendar (iCal) message that includes a payload, attackers can trigger automatic script execution in the webmail session of the user upon opening the message, leading to unauthorized data access and potential exploitation of the Content-Security-Policy's leniency.
Affected Version(s)
Smartermail 0
