CVE-2025-46611

Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via a crafted script.
Configurations

Configuration 1 (hide)

cpe:2.3:a:artec-it:ema:6.92:*:*:*:*:*:*:*

History

02 Jul 2025, 01:02

Type Values Removed Values Added
CPE cpe:2.3:a:artec-it:ema:6.92:*:*:*:*:*:*:*
Summary
  • (es) La vulnerabilidad de Cross Site Scripting en ARTEC EMA Mail v6.92 permite a un atacante ejecutar código arbitrario a través de un script especialmente manipulado.
References () https://www.artec-it.com/en-us/ema.html - () https://www.artec-it.com/en-us/ema.html - Product
References () https://www.syss.de/pentest-blog/csrf-und-xss-schwachstelle-in-ema-mail-von-artec-it-solutions-syss-2025-020/-021 - () https://www.syss.de/pentest-blog/csrf-und-xss-schwachstelle-in-ema-mail-von-artec-it-solutions-syss-2025-020/-021 - Third Party Advisory
First Time Artec-it
Artec-it ema

12 May 2025, 22:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

12 May 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-12 15:16

Updated : 2025-07-02 01:02


NVD link : CVE-2025-46611

Mitre link : CVE-2025-46611

CVE.ORG link : CVE-2025-46611


JSON object : View

Products Affected

artec-it

  • ema
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')