CVE-2025-2150

The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which will be executed in the recipient's browser when they view the email.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hgiga:c\&cm\@il:-:*:*:*:*:*:*:*

History

24 Mar 2025, 14:06

Type Values Removed Values Added
First Time Hgiga c\&cm\@il
Hgiga
Summary
  • (es) El C&Cm@il de HGiga tiene una vulnerabilidad de Cross-Site Scripting (XSS) Almacenado, que permite a atacantes remotos con privilegios regulares enviar correos electrónicos que contienen código JavaScript malicioso, que se ejecutará en el navegador del destinatario cuando vea el correo electrónico.
References () https://www.twcert.org.tw/en/cp-139-10005-05e0f-2.html - () https://www.twcert.org.tw/en/cp-139-10005-05e0f-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-10004-99474-1.html - () https://www.twcert.org.tw/tw/cp-132-10004-99474-1.html - Third Party Advisory
CPE cpe:2.3:a:hgiga:c\&cm\@il:-:*:*:*:*:*:*:*

10 Mar 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-10 08:15

Updated : 2025-03-24 14:06


NVD link : CVE-2025-2150

Mitre link : CVE-2025-2150

CVE.ORG link : CVE-2025-2150


JSON object : View

Products Affected

hgiga

  • c\&cm\@il
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')