CVE-2025-2150
Estado: AnalizadaMedia (5.4)—
The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which will be executed in the recipient's browser when they view the email.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.26%
- Percentil entre todas las CVEs puntuadas: 17
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-2150",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-2150",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-03-10T15:34:19.659333Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "twcert@cert.org.tw",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "twcert@cert.org.tw",
"affectedData": [
{
"vendor": "HGiga",
"product": "C&Cm@il",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.0-238",
"versionType": "custom"
}
],
"packageName": "MailK-mail",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-03-10T08:15:11.917",
"references": [
{
"url": "https://www.twcert.org.tw/en/cp-139-10005-05e0f-2.html",
"tags": [
"Third Party Advisory"
],
"source": "twcert@cert.org.tw"
},
{
"url": "https://www.twcert.org.tw/tw/cp-132-10004-99474-1.html",
"tags": [
"Third Party Advisory"
],
"source": "twcert@cert.org.tw"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "twcert@cert.org.tw",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which will be executed in the recipient's browser when they view the email."
},
{
"lang": "es",
"value": "El C&Cm@il de HGiga tiene una vulnerabilidad de Cross-Site Scripting (XSS) Almacenado, que permite a atacantes remotos con privilegios regulares enviar correos electrónicos que contienen código JavaScript malicioso, que se ejecutará en el navegador del destinatario cuando vea el correo electrónico."
}
],
"lastModified": "2026-06-17T09:06:25.450",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hgiga:c\\&cm\\@il:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "177F8E98-5F0D-4D4C-9386-8FDC6614AF5D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "twcert@cert.org.tw"
}