Collax Security Gateway: stored cross-site scripting through the mail envelope sender in the held-mail queue
An unauthenticated SMTP sender sets a crafted envelope sender and plants stored script that runs in the admin origin when a mail administrator opens the held-mail queue.
Advisory ID: TP-2026-065
Product: Collax Security Gateway (German UTM, firewall, mail and SSL-VPN appliance; also affects Collax Business Server and Groupware Suite)
Vulnerability type: Stored cross-site scripting (CWE-79)
CVE: pending (MITRE CNA-LR)
CVSS 3.1: 8.0 (High) · CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Vendor advisory: Collax release notes CSG 7.2.48
Affected versions: 7.2.46 and earlier
Fixed in: 7.2.48
Reported: 01 September 2026
Summary
Collax Security Gateway holds suspicious messages in a quarantine a mail administrator reviews in the admin interface. The held-mail table shows each message's envelope sender, the SMTP MAIL FROM set by the remote, unauthenticated sending host. The quarantine loader reads the sender via postcat and stores it verbatim, trimming whitespace only. The accessor returns the value raw, the queue is passed to the qooxdoo client with no HTML encoding, and its cell-renderer map routes the email type to a raw-HTML renderer. With no CSP, an unauthenticated sender thereby plants stored markup that renders in the :8001 admin origin.
Root cause
suwrap/holdq.pl:91-92 reads the Postfix envelope sender via postcat and stores it verbatim in the queue item, whitespace-trimmed only, so < > " = survive.
AKLib/Mail/MailQHold.pm:20-22 sub sender returns that value raw, and loadMailQHold JSON-encodes the queue to the client with no HTML encoding.
The held-mail form declares the column as
The qooxdoo admin bundle escapes only the types plain, bytesize, boolean, checkbox and date; every other type, email included, falls through to default:d=new ak.ui.table.cellrenderer.Html (html/gui/qx/ak/index.js), which writes the value into a
The raw-HTML renderer is intentional (an explicit type='html' is used elsewhere); the defect is the attacker-controlled envelope sender reaching it through the fail-open type-to-renderer mapping.
Proof of Concept
Schematically: the envelope sender is set as an RFC 5321 quoted-string so HTML metacharacters are legal in the local part.
MAIL FROM:<"<event-handler payload>"@evil.example>
The message lands in the HOLD quarantine. When a mail administrator opens the held-mail queue, the Html cell renderer writes the sender as innerHTML and fires the payload in the :8001 admin origin. With no CSP the script reads the non-HttpOnly auth_cookie (base64(user:password)). The server-side emit path was verified statically against source; browser execution, the sender surviving Postfix, and the mail-gateway HOLD precondition require a booted appliance.
Impact
- Stored script in the :8001 admin origin, triggered when a mail administrator reviews the quarantine.
- No CSP anywhere on the appliance, so the injected markup renders.
- The auth_cookie is base64(user:password) and not HttpOnly, so the script discloses the plaintext admin password.
- The source is an unauthenticated remote SMTP sender; the payload persists in the quarantine until reviewed.
- Conditional on the appliance running as a filtering mail gateway with HOLD quarantine active.
References
Is Something Like This in Your Software?
Our team found this vulnerability during its work. Have your applications tested by the same specialists, with a penetration test from turingpoint.
