天下漏洞,尽知其名
MEDIUM

CVE-2026-104083 SmarterMail 存储型变异 XSS 漏洞

影响攻击者可在收件人 Webmail 会话中执行任意脚本并窃取数据

AI 研判

SmarterMail build 9777 之前版本存在存储型变异 XSS 漏洞。攻击者通过构造包含 MathML 外来内容(<math><mtext>)嵌套载荷的 iCal 日历消息,绕过自定义 HTML 清洗器。当收件人打开该消息时,脚本在 /interface/message-iframe 中自动执行。

影响范围

SmarterMail

SmarterMail build 9777 之前的版本受影响,具体版本范围以官方公告为准。

漏洞详情

漏洞属于存储型变异 XSS(mXSS)。清洗器将 <math><mtext> 内的内容视为惰性 CDATA 文本,但浏览器重新解析时将其当作活动标记,导致 <img src="x"> 等载荷被激活执行。攻击者只需发送特制 iCal 日历消息,收件人打开即触发。

利用条件与风险

利用需受害者打开恶意日历消息,无需其他交互;由于界面 CSP 较为宽松,脚本可执行并外传数据,实战风险中等。

修复建议

升级至 SmarterMail build 9777 或更高版本;暂无公开临时缓解措施,可考虑对日历消息内容进行额外过滤或收紧 CSP。

原始情报

SmarterMail before build 9777 contains a stored mutation cross-site scripting vulnerability that allows remote attackers to inject executable script by placing payloads inside a element nested within MathML foreign content (), which the custom HTML sanitizer treats as inert CDATA text but browsers reparse as live markup. Attackers can deliver a crafted calendar (iCal) message containing an payload that executes automatically in the recipient’s webmail session at /interface/message-iframe when the message is opened, enabling script execution and data exfiltration unconstrained by the interface’s permissive Content-Security-Policy.