PT-2025-18713 · Sematell · Sematell Replyone

CVE-2024-48906

·

Publicado

2025-05-01

·

Atualizado

2025-05-03

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sematell ReplyOne version 7.4.3.0
Description The issue allows for cross-site scripting (XSS) attacks through a ReplyDesk e-mail attachment name. This means an attacker could potentially inject malicious scripts into the system by manipulating the name of an attachment in an email, leading to the execution of unwanted actions on the user's browser.
Recommendations For Sematell ReplyOne version 7.4.3.0, consider validating and sanitizing all user-input data, including email attachment names, to prevent XSS attacks. As a temporary workaround, restrict the ability to upload or send emails with attachments until a patch is available.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-48906

Produtos afetados

Sematell Replyone