Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18797 | Mail-0's Zero is an open-source email solution. In version 0.8 it's possible for an attacker to craft an email that executes javascript leading to session hijacking due to improper sanitization. This issue has been patched in version 0.81. |
Mon, 23 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 21 Jun 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mail-0's Zero is an open-source email solution. In version 0.8 it's possible for an attacker to craft an email that executes javascript leading to session hijacking due to improper sanitization. This issue has been patched in version 0.81. | |
| Title | Mail-0 Zero Session Hijacking Via Email | |
| Weaknesses | CWE-1384 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-23T17:41:29.958Z
Reserved: 2025-06-18T03:55:52.035Z
Link: CVE-2025-52557
Updated: 2025-06-23T17:41:20.499Z
Status : Deferred
Published: 2025-06-21T02:15:20.107
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-52557
No data.
OpenCVE Enrichment
No data.
EUVD