CVE-2022-50908

Source
https://cve.org/CVERecord?id=CVE-2022-50908
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50908.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-50908
Published
2026-01-13T22:51:49.736Z
Modified
2026-07-15T01:48:58.466030560Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Mailhog 1.0.1 - Stored Cross-Site Scripting (XSS)
Details

Mailhog 1.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through email attachments. Attackers can send crafted emails with XSS payloads to execute arbitrary API calls, including message deletion and browser manipulation.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50908.json"
}
References

Affected packages

Git / github.com/mailhog/mailhog

Affected ranges

Type
GIT
Repo
https://github.com/mailhog/mailhog
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "1.0.1"
        },
        {
            "last_affected": "1.0.1"
        }
    ]
}

Affected versions

1.*
1.0.1
v1.*
v1.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50908.json"