- Description
- The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which will be executed in the recipient's browser when they view the email.
- Source
- twcert@cert.org.tw
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 5.4
- Impact score
- 2.7
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- twcert@cert.org.tw
- CWE-79
- Hype score
- Not currently trending
CVE-2025-2150 03/10/2025 08:15:11 AM BaseSeverity: MEDIUM The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious ... https://t.co/72POfKMrt8
@CVETracker
10 Mar 2025
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-2150 🟠 MEDIUM (5.4) 🏢 HGiga - C&Cm@il 🏗️ 0 🔗 https://t.co/j9UZoBlFct 🔗 https://t.co/JJ7ISSUAK7 #CyberCron #VulnAlert #InfoSec https://t.co/Tr1ebyUFdb
@cybercronai
10 Mar 2025
19 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-2150 Stored Cross-Site Scripting (XSS) in HGiga C&Cm@il Enables Remote Malicious Code Injection https://t.co/VEw9FZk94v
@VulmonFeeds
10 Mar 2025
63 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-2150 The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious Java… https://t.co/tVy1b6paVQ
@CVEnew
10 Mar 2025
427 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hgiga:c\\&cm\\@il:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "177F8E98-5F0D-4D4C-9386-8FDC6614AF5D"
}
],
"operator": "OR"
}
]
}
]