Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-977w-cv9x-3pr9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.

Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.

EPSS

Процентиль: 75%
0.00877
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 5 лет назад

Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.

EPSS

Процентиль: 75%
0.00877
Низкий

Дефекты

CWE-79