•  
      request #42177 Content injection via emails sent by the mass emailing features
    Infos
    #42177
    Thomas Gerbet (tgerbet)
    2025-03-04 17:38
    2025-02-26 10:03
    43845
    Details
    Content injection via emails sent by the mass emailing features

    The mass emailing features do not sanitize the content of the HTML emails.

    Impact

    A malicious user could use this issue to facilitate a phishing attempt or to indirectly exploit issues in the recipients mail clients.

    CVSSv3.1 score: 4.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N)

    References

    CWE 79
    OWASP Cross-site Scripting
    CVE-2025-27156

    Acknowledgements

    This issue has been found thanks to Psalm 6 taint analysis feature.

    Other
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2025-02-26
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-02-28 18:05

    CVE-2025-27156 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes