Описание
iRedAdmin before 2.6 allows XSS, e.g., via order_name.
iRedAdmin before 2.6 allows XSS, e.g., via order_name.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2024-47227
- https://github.com/iredmail/iRedAdmin/commit/3c72b438d412ea3ee0270f6956e19b1098c19191
- https://github.com/iredmail/iRedAdmin/commit/b537e71ecf522d7f10180f5f0aab4a98a881893a
- https://docs.iredmail.org/upgrade.iredmail.1.6.8-1.7.0.html#upgrade-iredadmin-open-source-edition-to-the-latest-stable-release-26
- https://github.com/iredmail/iRedAdmin/compare/2.5...2.6
- https://www.iredmail.org
Связанные уязвимости
CVSS3: 6.1
nvd
больше 1 года назад
iRedAdmin before 2.6 allows XSS, e.g., via order_name.