Unknown · Mail-0'S Zero · CVE-2025-52557
Name of the Vulnerable Software and Affected Versions:
Mail-0's Zero versions 0.8
Description:
The issue is related to improper sanitization, allowing an attacker to craft an email that executes javascript, leading to session hijacking. This is a Stored XSS Vulnerability in the Mail-0's Zero Email Solution.
Recommendations:
For version 0.8, update to version 0.81 to resolve the issue. As a temporary workaround, consider disabling javascript execution in emails until the patch is applied. Restrict access to sensitive email accounts to minimize the risk of session hijacking.