vulnerability
FreeBSD: VID-3E917407-4B3F-11EF-8E49-001999F8D30B: Mailpit -- Content Security Policy XSS
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
6 | (AV:N/AC:M/Au:N/C:P/I:P/A:N) | 07/26/2024 | 07/26/2024 | 02/19/2025 |
Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:N)
Published
07/26/2024
Added
07/26/2024
Modified
02/19/2025
Description
Mailpit developer reports:
A vulnerability was discovered which allowed a bad
actor with SMTP access to Mailpit to bypass the Content
Security Policy headers using a series of crafted HTML
messages which could result in a stored XSS attack via
the web UI.
Solution
freebsd-upgrade-package-mailpit
References

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.