Home
MEDIUM: 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 15.0.3
affected
Description
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new CA certificates.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-Site Scripting')
Product status
Any version before 15.0.3
Timeline
| 2025-10-31: | Vulnerability disclosed to SEPPmail |
| 2026-03-03: | Version 15.0.3 released |
Credits
Andris Suter-Dörig
Matteo Scarlata
Kenny Paterson
References
downloads.seppmail.com/extrelnotes/150/ERN15.0.html