Unrated severityNVD Advisory· Published Aug 20, 2024· Updated Nov 26, 2024
[20240803] - Core - XSS in HTML Mail Templates
CVE-2024-27186
Description
The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
Affected products
1- Range: 4.0.0-4.4.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.