CVE-2023-48114
SmarterTools SmarterMail vulnerability analysis and mitigation

Overview

SmarterTools SmarterMail versions 8495 through 8664 before 8747 contains a stored Cross-Site Scripting (XSS) vulnerability. The vulnerability exists because the application attempts to allow youtube.com URLs but fails to properly validate URLs, allowing an attacker to bypass restrictions using the @ character followed by an attacker-controlled domain name. This vulnerability was discovered and disclosed on December 21, 2023 (NVD).

Technical details

The vulnerability stems from a flaw in the application's Anti-XSS mechanism. The sanitization function uses specific whitelists and blacklists to filter content, but has a flaw in its URL validation process. The application accepts URLs in the format 'youtube.com@attacker.com' as valid, bypassing the intended restrictions. The vulnerability can be exploited by using image/svg+xml content type and uploading an SVG document containing malicious code. The application's Content Security Policy (CSP) with frame-ancestors directive set to 'self' requires the payload to be hosted on the mail server itself (Write-Ups).

Impact

The vulnerability allows attackers with normal-access accounts to potentially take over other users' accounts by sending emails containing malicious JavaScript code. When victims open their inbox, the malicious code executes, potentially allowing attackers to extract the victim's accessToken and refreshToken (Write-Ups).

Exploitability

The vulnerability has been demonstrated to be exploitable through a proof-of-concept that involves uploading a malicious SVG file to the server and crafting a specific payload that executes when victims view their inbox. The exploit requires the attacker to have a normal user account on the system (Write-Ups).

Mitigation and workarounds

The vulnerability has been patched in SmarterMail Build 8747. Organizations should upgrade to this version or later to mitigate the risk. No other workarounds are documented (Release Notes).

Additional resources


SourceThis report was generated using AI

Related SmarterTools SmarterMail vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-24423CRITICAL9.3
  • SmarterTools SmarterMail logoSmarterTools SmarterMail
  • cpe:2.3:a:smartertools:smartermail
YesYesJan 23, 2026
CVE-2026-7807HIGH8.7
  • SmarterTools SmarterMail logoSmarterTools SmarterMail
  • cpe:2.3:a:smartertools:smartermail
NoYesMay 08, 2026
CVE-2026-40514HIGH8.2
  • SmarterTools SmarterMail logoSmarterTools SmarterMail
  • cpe:2.3:a:smartertools:smartermail
NoYesApr 27, 2026
CVE-2026-26930HIGH7.2
  • SmarterTools SmarterMail logoSmarterTools SmarterMail
  • cpe:2.3:a:smartertools:smartermail
NoYesFeb 16, 2026
CVE-2026-25067MEDIUM6.9
  • SmarterTools SmarterMail logoSmarterTools SmarterMail
  • cpe:2.3:a:smartertools:smartermail
NoYesJan 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management