vulnerability

FreeBSD: VID-3E917407-4B3F-11EF-8E49-001999F8D30B: Mailpit -- Content Security Policy XSS

Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:N)
Published
07/26/2024
Added
07/26/2024
Modified
02/19/2025

Description



Mailpit developer reports:



A vulnerability was discovered which allowed a bad


actor with SMTP access to Mailpit to bypass the Content


Security Policy headers using a series of crafted HTML


messages which could result in a stored XSS attack via


the web UI.




Solution

freebsd-upgrade-package-mailpit

References

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.