CVE-2026-40873 | mailcow mailcow-dockerized prior 2026-03b Attachment cross site scripting (GHSA-2xjc-rg88-jvpp)
A vulnerability was found in mailcow mailcow-dockerized and classified as problematic. This affects an unknown function of the component Attachment Handler. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-40873. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.