CVE-2025-2150

The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which will be executed in the recipient's browser when they view the email.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hgiga:c\&cm\@il:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-10 08:15

Updated : 2025-03-24 14:06


NVD link : CVE-2025-2150

Mitre link : CVE-2025-2150

CVE.ORG link : CVE-2025-2150


JSON object : View

Products Affected

hgiga

  • c\&cm\@il
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')