PT-2026-22720 · Unknown · Mail-Parser
Ravishanker Kusuma
·
Publicado
2026-03-03
·
Atualizado
2026-03-13
·
CVE-2026-3455
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
mailparser versions prior to 3.9.3
Description
The package mailparser is susceptible to Cross-site Scripting (XSS) due to insufficient sanitization of URLs within email content. Specifically, the
textToHtml() function does not properly handle URLs, allowing an attacker to inject malicious JavaScript code by adding extra quotes to the URL. This can lead to the execution of arbitrary scripts in a victim's browser.Recommendations
Update mailparser to version 3.9.3 or later.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mail-Parser