Описание
Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML within the body of an email via an IMG element with both single quotes and double quotes.
Ссылки
- Vendor Advisory
- ExploitTechnical DescriptionThird Party Advisory
- Vendor Advisory
- ExploitTechnical DescriptionThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.8.0.1 (включая)
cpe:2.3:a:atmail:atmail:*:*:*:*:*:*:*:*
EPSS
Процентиль: 49%
0.0026
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
debian
больше 8 лет назад
Cross-site scripting (XSS) vulnerability in atmail prior to version 7. ...
CVSS3: 6.1
github
больше 3 лет назад
Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML within the body of an email via an IMG element with both single quotes and double quotes.
EPSS
Процентиль: 49%
0.0026
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79