Show filters
45 Total Results
Displaying 1-10 of 45
Sort by:
Attacker Value
Unknown

CVE-2023-48116

Disclosure Date: December 21, 2023 (last updated January 05, 2024)
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS via a crafted description of a Calendar appointment.
Attacker Value
Unknown

CVE-2023-48115

Disclosure Date: December 21, 2023 (last updated January 05, 2024)
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.
Attacker Value
Unknown

CVE-2023-48114

Disclosure Date: December 21, 2023 (last updated January 05, 2024)
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.
Attacker Value
Unknown

CVE-2022-24387

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010
Attacker Value
Unknown

CVE-2022-24385

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
Attacker Value
Unknown

CVE-2022-24386

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
Stored XSS in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
Attacker Value
Unknown

CVE-2022-24384

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
Attacker Value
Unknown

CVE-2021-43977

Disclosure Date: November 17, 2021 (last updated February 23, 2025)
SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows XSS.
Attacker Value
Unknown

CVE-2021-32234

Disclosure Date: November 17, 2021 (last updated October 07, 2023)
SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution.
Attacker Value
Unknown

CVE-2021-40377

Disclosure Date: September 08, 2021 (last updated February 23, 2025)
SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus allowing one to inject HTML and/or JavaScript into a page that will then be processed and stored by the application.