Descripción
Mailhog 1.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through email attachments. Attackers can send crafted emails with XSS payloads execute arbitrary API calls, including message deletion and browser manipulation.
https://github.com/mailhog/MailHog
https://www.exploit-db.com/exploits/50971
https://www.shodan.io/search?query=mailhog
https://www.vulncheck.com/advisories/mailhog-stored-cross-site-scripting-xss