Cross-Site Scripting Vulnerabilities in Gophish by Gophish
CVE-2026-107272
2.3LOW
Key Information:
Badges
๐พ Exploit Exists
What is CVE-2026-107272?
Gophish versions up to 0.12.1 are susceptible to both stored and reflected cross-site scripting (XSS) vulnerabilities. These vulnerabilities arise from the improper handling of error messages returned by malicious SMTP servers, which can lead to script injection. Attackers who control or intercept the SMTP server used by Gophish can exploit this flaw when administrators view campaign results or send test emails. This exploitation could result in the unauthorized access to sensitive information, including API keys.
Affected Version(s)
gophish 0 <= 0.12.1
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Sohaib Harraoui (Ostorlab)
