CVE-2023-48114
SmarterTools SmarterMail vulnerability analysis and mitigation

Overview

SmarterTools SmarterMail versions 8495 through 8664 before 8747 contains a stored Cross-Site Scripting (XSS) vulnerability. The vulnerability exists because the application attempts to allow youtube.com URLs but fails to properly validate URLs, allowing an attacker to bypass restrictions using the @ character followed by an attacker-controlled domain name. This vulnerability was discovered and disclosed on December 21, 2023 (NVD).

Technical details

The vulnerability stems from a flaw in the application's Anti-XSS mechanism. The sanitization function uses specific whitelists and blacklists to filter content, but has a flaw in its URL validation process. The application accepts URLs in the format 'youtube.com@attacker.com' as valid, bypassing the intended restrictions. The vulnerability can be exploited by using image/svg+xml content type and uploading an SVG document containing malicious code. The application's Content Security Policy (CSP) with frame-ancestors directive set to 'self' requires the payload to be hosted on the mail server itself (Write-Ups).

Impact

The vulnerability allows attackers with normal-access accounts to potentially take over other users' accounts by sending emails containing malicious JavaScript code. When victims open their inbox, the malicious code executes, potentially allowing attackers to extract the victim's accessToken and refreshToken (Write-Ups).

Mitigation and workarounds

The vulnerability has been patched in SmarterMail Build 8747. Organizations should upgrade to this version or later to mitigate the risk. No other workarounds are documented (Release Notes).

Additional resources


SourceThis report was generated using AI

Related SmarterTools SmarterMail vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-52691CRITICAL10
  • SmarterTools SmarterMailSmarterTools SmarterMail
  • cpe:2.3:a:smartertools:smartermail
NoYesDec 29, 2025
CVE-2021-43977MEDIUM6.1
  • SmarterTools SmarterMailSmarterTools SmarterMail
  • cpe:2.3:a:smartertools:smartermail
NoYesNov 17, 2021
CVE-2023-48116MEDIUM5.4
  • SmarterTools SmarterMailSmarterTools SmarterMail
  • cpe:2.3:a:smartertools:smartermail
NoYesDec 21, 2023
CVE-2023-48115MEDIUM5.4
  • SmarterTools SmarterMailSmarterTools SmarterMail
  • cpe:2.3:a:smartertools:smartermail
NoYesDec 21, 2023
CVE-2023-48114MEDIUM5.4
  • SmarterTools SmarterMailSmarterTools SmarterMail
  • cpe:2.3:a:smartertools:smartermail
NoYesDec 21, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management