vulnerability

FreeBSD: VID-3e917407-4b3f-11ef-8e49-001999f8d30b: Mailpit -- Content Security Policy XSS

Severity
5
CVSS
(AV:N/AC:M/Au:S/C:P/I:P/A:N)
Published
Jul 26, 2024
Added
Jul 26, 2024
Modified
Dec 10, 2025

Description

Mailpit developer reports: A vulnerability was discovered which allowed a bad actor with SMTP access to Mailpit to bypass the Content Security Policy headers using a series of crafted HTML messages which could result in a stored XSS attack via the web UI.

Solution

freebsd-upgrade-package-mailpit

References

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.