CVE detail
CVE-2023-48114 — CVE-2023-48114
Published 2023-12-21 · Modified 2026-06-17 · Vendor smartertools · Product smartermail · Source nvd
MEDIUM
severity
CVSS-derived band
0.0036
EPSS probability
exploitation probability, 30d
28.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References