VulnerabilityModified
CVE-2021-40377
SmarterTools SmarterMail 16.x before build 7866 has stored XSS.
MEDIUM 5.4EPSS 0.47%
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus allowing one to inject HTML and/or JavaScript into a page that will then be processed and stored by the application.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.47% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- smartertools/smartermail
- Source
- cve@mitre.org
References
- https://www.smartertools.com/smartermail/release-notes/currentRelease Notes, Vendor Advisory
- https://www.smartertools.com/smartermail/release-notes/currentRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.