Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104083— SmarterMail < Build 9777 Stored Mutation XSS via MathML Foreign Content

Quick assessment

Affected
Smartertools Smartermail
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在构建版本低于 9777 的 SmarterMail 中,存在一个存储型变异型跨站脚本(XSS)漏洞。该漏洞允许远程攻击者通过在 元素内注入恶意脚本载荷,并利用嵌套在 MathML 外部内容中的结构(即 )来实施攻击。SmarterMail 自定义的 HTML 清洗器将此类内容误认为是惰性 CDATA 文本,而浏览器则会将其重新解析为可执行的标记(live markup),从而导致脚本执行。 攻击者可以构造一个包含恶意 载荷的日历(iCal)消息,并通过电子邮件发送给受害者。当收件人在 路径下使用 Webmail

CVSS 6.1 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104083

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SmarterMail < Build 9777 Stored Mutation XSS via MathML Foreign Content
Source: CVE Program / CVE List V5
Vulnerability Description
SmarterMail before build 9777 contains a stored mutation cross-site scripting vulnerability that allows remote attackers to inject executable script by placing payloads inside a <style> element nested within MathML foreign content (<math><mtext><mglyph>), which the custom HTML sanitizer treats as inert CDATA text but browsers reparse as live markup. Attackers can deliver a crafted calendar (iCal) message containing an <img src=x onerror=...> payload that executes automatically in the recipient's webmail session at /interface/message-iframe when the message is opened, enabling script execution and data exfiltration unconstrained by the interface's permissive Content-Security-Policy.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Smartertools Smartermail 0 ~ Build 9777 -

II. Public POCs for CVE-2026-104083

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104083

请登录查看更多情报信息。

Other References for CVE-2026-104083 (2)

Same Patch Batch · Smartertools · 2026-10-09 · 3 CVEs total

CVE-2026-104084 8.8 HIGH SmarterMail < Build 9777 Stale JWT Role Claim Privilege Escalation via Refresh Token
CVE-2026-104082 7.2 HIGH SmarterMail < Build 9777 SysAdmin Remote Code Execution via Volume Mount

IV. Related Vulnerabilities

V. Comments for CVE-2026-104083

No comments yet


Leave a comment