go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

HGiga C&Cm@il - Stored Cross-Site Scripting

TVN ID TVN-202503001
CVE ID CVE-2025-2150
CVSS 5.4 (Medium)
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected Products Package MailK-mail before version 1.0-238
Description The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which will be executed in the recipient's browser when they view the email.
Solution Upadate package Mailk-mail to version 1.0-238 or later.
Credit AAA Security Technology
Public Date 2025-03-10
Top