PT-2025-4889 · Unknown · Emailshroud

Soprobro

·

Published

2025-01-16

·

Updated

2025-05-26

·

CVE-2025-23456

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions EmailShroud versions prior to 2.2.1 EmailShroud version 2.2.1
Description The issue is a Cross-Site Request Forgery (CSRF) vulnerability that allows Reflected XSS. This means an attacker can trick a user into performing unintended actions on a web application, and also inject malicious code that will be executed by the user's browser.
Recommendations For versions prior to 2.2.1, update to version 2.2.1 or later to resolve the issue. For version 2.2.1, consider disabling any functionality that may be related to the CSRF vulnerability until a patch is available.

Fix

RCE

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-23456

Affected Products

Emailshroud