PT-2026-25008 · Git+1 · Postal
Adamcoke
·
Publicado
2026-03-12
·
Atualizado
2026-03-12
·
CVE-2026-25529
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Postal versions prior to 3.3.5
Description
Postal is an open source SMTP server. Versions prior to 3.3.5 contain a HTML injection issue that allows unescaped data to be included in the administration interface. The primary method for adding unescaped data is through the
send/raw method of the API endpoint /api/v1/send/raw. This could allow arbitrary HTML to be injected into the page, potentially modifying the page in a misleading way or enabling the execution of unauthorized javascript.Recommendations
Upgrade to Postal version 3.3.5 or later.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Postal