CVE-2025-2150

The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which will be executed in the recipient's browser when they view the email.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hgiga:c\&cm\@il:-:*:*:*:*:*:*:*

History

24 Mar 2025, 14:06

Type Values Removed Values Added
First Time Hgiga
Hgiga c\&cm\@il
References () https://www.twcert.org.tw/tw/cp-132-10004-99474-1.html - () https://www.twcert.org.tw/tw/cp-132-10004-99474-1.html - Third Party Advisory
References () https://www.twcert.org.tw/en/cp-139-10005-05e0f-2.html - () https://www.twcert.org.tw/en/cp-139-10005-05e0f-2.html - Third Party Advisory
CPE cpe:2.3:a:hgiga:c\&cm\@il:-:*:*:*:*:*:*:*

10 Mar 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-10 08:15

Updated : 2025-03-24 14:06


NVD link : CVE-2025-2150

Mitre link : CVE-2025-2150


JSON object : View

Products Affected

hgiga

  • c\&cm\@il
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')