The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which will be executed in the recipient's browser when they view the email.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Mar 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hgiga
Hgiga c\&cm\@il |
|
| CPEs | cpe:2.3:a:hgiga:c\&cm\@il:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Hgiga
Hgiga c\&cm\@il |
Mon, 10 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Mar 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which will be executed in the recipient's browser when they view the email. | |
| Title | HGiga C&Cm@il - Stored Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published: 2025-03-10T07:12:22.552Z
Updated: 2025-03-10T15:34:31.590Z
Reserved: 2025-03-10T06:22:23.896Z
Link: CVE-2025-2150
Updated: 2025-03-10T15:34:28.394Z
Status : Analyzed
Published: 2025-03-10T08:15:11.917
Modified: 2025-03-24T14:06:07.687
Link: CVE-2025-2150
No data.
ReportizFlow