PT-2025-18713 · Sematell · Sematell Replyone
Published
2025-05-01
·
Updated
2025-05-03
·
CVE-2024-48906
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sematell ReplyOne version 7.4.3.0
Description
The issue allows for cross-site scripting (XSS) attacks through a ReplyDesk e-mail attachment name. This means an attacker could potentially inject malicious scripts into the system by manipulating the name of an attachment in an email, leading to the execution of unwanted actions on the user's browser.
Recommendations
For Sematell ReplyOne version 7.4.3.0, consider validating and sanitizing all user-input data, including email attachment names, to prevent XSS attacks. As a temporary workaround, restrict the ability to upload or send emails with attachments until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sematell Replyone