Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 23, 2016 |
| Debian | — | Upgrade kdepimlibsUpgrade kcoreaddons | Mar 31, 2017 | Oct 21, 2016 |
| Suse | — | Upgrade kcoreaddons-develUpgrade libKF5CoreAddons5Upgrade kcoreaddons-langUpgrade kcoreaddons | Nov 3, 2016 | Oct 18, 2016 |
| Ubuntu | — | Upgrade libkpimutils4 | Jul 1, 2017 | Oct 12, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub