CVE-2026-104083 PUBLISHED

SmarterMail < Build 9777 Stored Mutation XSS via MathML Foreign Content

Assigner: VulnCheck
Reserved: 01.10.2026 Published: 09.10.2026 Updated: 09.10.2026

SmarterMail before build 9777 contains a stored mutation cross-site scripting vulnerability that allows remote attackers to inject executable script by placing payloads inside a <style> element nested within MathML foreign content (<math><mtext><mglyph>), which the custom HTML sanitizer treats as inert CDATA text but browsers reparse as live markup. Attackers can deliver a crafted calendar (iCal) message containing an <img src=x onerror=...> payload that executes automatically in the recipient's webmail session at /interface/message-iframe when the message is opened, enabling script execution and data exfiltration unconstrained by the interface's permissive Content-Security-Policy.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.3

Product Status

Vendor Smartertools
Product Smartermail
Versions Default: unaffected
  • affected from 0 to Build 9777 (excl.)

Credits

  • evan finder

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE