ZeroHour

CVE-2025-2150

CVSS 3.1
5.4 medium
EPSS
<1%p17
Published
()
Modified
Description

The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which will be executed in the recipient's browser when they view the email.

Vendors
hgiga
Products
c\&cm\@il
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.