在构建版本低于 9777 的 SmarterMail 中,存在一个存储型变异型跨站脚本(XSS)漏洞。该漏洞允许远程攻击者通过在 元素内注入恶意脚本载荷,并利用嵌套在 MathML 外部内容中的结构(即 )来实施攻击。SmarterMail 自定义的 HTML 清洗器将此类内容误认为是惰性 CDATA 文本,而浏览器则会将其重新解析为可执行的标记(live markup),从而导致脚本执行。 攻击者可以构造一个包含恶意 载荷的日历(iCal)消息,并通过电子邮件发送给受害者。当收件人在 路径下使用 Webmail
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Smartertools | Smartermail | 0 ~ Build 9777 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104084 | 8.8 HIGH | SmarterMail < Build 9777 Stale JWT Role Claim Privilege Escalation via Refresh Token |
| CVE-2026-104082 | 7.2 HIGH | SmarterMail < Build 9777 SysAdmin Remote Code Execution via Volume Mount |
No comments yet