PT-2026-25008 · Git+1 · Postal

Adamcoke

·

Publicado

2026-03-12

·

Atualizado

2026-03-12

·

CVE-2026-25529

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Postal versions prior to 3.3.5
Description Postal is an open source SMTP server. Versions prior to 3.3.5 contain a HTML injection issue that allows unescaped data to be included in the administration interface. The primary method for adding unescaped data is through the send/raw method of the API endpoint /api/v1/send/raw. This could allow arbitrary HTML to be injected into the page, potentially modifying the page in a misleading way or enabling the execution of unauthorized javascript.
Recommendations Upgrade to Postal version 3.3.5 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25529
GHSA-5F4R-5JPR-RFHC

Produtos afetados

Postal