SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-40377

SmarterTools SmarterMail 16.x before build 7866 has stored XSS.

MEDIUM 5.4EPSS 0.47%

Does this matter?

Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.

Description

SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus allowing one to inject HTML and/or JavaScript into a page that will then be processed and stored by the application.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.47% probability · 39th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
smartertools/smartermail
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.