在 SmarterMail build 9777 之前的版本中,存在一个远程代码执行漏洞。该漏洞允许持有 SysAdmin 作用域访问令牌的攻击者,通过 domain-put 端点,使用受信任的 Scripts 目录内的任意 FileStore 根路径配置新的邮件域,从而绕过 Volume Mount 脚本目录的隔离控制。攻击者可以通过 AddOrUpdateMount 端点泄露 Scripts 目录的路径,通过 global-mail 端点清除上传扩展名的黑名单,然后通过常规的邮件文件存储上传 API 上传恶意脚
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Smartertools | Smartermail | 0 ~ Build 9777 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104084 | 8.8 HIGH | SmarterMail < Build 9777 Stale JWT Role Claim Privilege Escalation via Refresh Token |
| CVE-2026-104083 | 6.1 MEDIUM | SmarterMail < Build 9777 Stored Mutation XSS via MathML Foreign Content |
No comments yet