Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Dec 23, 2016 | |
| Debian | debian-upgrade-kcoreaddonsdebian-upgrade-kdepimlibs | Mar 31, 2017 | Oct 21, 2016 | |
| Suse | — | suse-upgrade-kcoreaddonssuse-upgrade-kcoreaddons-develsuse-upgrade-kcoreaddons-langsuse-upgrade-libkf5coreaddons5 | Nov 3, 2016 | Oct 18, 2016 |
| Ubuntu | ubuntu-upgrade-libkpimutils4 | Jul 1, 2017 | Oct 12, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub