Mail-0's Zero is an open-source email solution. In version 0.8 it's possible for an attacker to craft an email that executes javascript leading to session hijacking due to improper sanitization. This issue has been patched in version 0.81.
History

Sat, 21 Jun 2025 02:00:00 +0000

Type Values Removed Values Added
Description Mail-0's Zero is an open-source email solution. In version 0.8 it's possible for an attacker to craft an email that executes javascript leading to session hijacking due to improper sanitization. This issue has been patched in version 0.81.
Title Mail-0 Zero Session Hijacking Via Email
Weaknesses CWE-1384
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-21T01:42:23.004Z

Updated: 2025-06-21T01:42:23.004Z

Reserved: 2025-06-18T03:55:52.035Z

Link: CVE-2025-52557

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-06-21T02:15:20.107

Modified: 2025-06-21T02:15:20.107

Link: CVE-2025-52557

cve-icon Redhat

No data.