SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.
| Software | From | Fixed in |
|---|---|---|
| smartertools / smartermail | 16.0.8495 | 16.0.8747 |