Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smartertools
Smartertools smartermail |
|
| Vendors & Products |
Smartertools
Smartertools smartermail |
Fri, 09 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SmarterMail before build 9777 contains a stored mutation cross-site scripting vulnerability that allows remote attackers to inject executable script by placing payloads inside a <style> element nested within MathML foreign content (<math><mtext><mglyph>), which the custom HTML sanitizer treats as inert CDATA text but browsers reparse as live markup. Attackers can deliver a crafted calendar (iCal) message containing an <img src=x onerror=...> payload that executes automatically in the recipient's webmail session at /interface/message-iframe when the message is opened, enabling script execution and data exfiltration unconstrained by the interface's permissive Content-Security-Policy. | |
| Title | SmarterMail < Build 9777 Stored Mutation XSS via MathML Foreign Content | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-09T15:06:57.154Z
Reserved: 2026-10-01T18:02:50.084Z
Link: CVE-2026-104083
No data.
Status : Awaiting Analysis
Published: 2026-10-09T16:17:20.993
Modified: 2026-10-09T17:06:17.770
Link: CVE-2026-104083
No data.
OpenCVE Enrichment
Updated: 2026-10-09T16:45:09Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')