Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-49077

Опубликовано: 30 нояб. 2023
Источник: nvd
CVSS3: 8.3
CVSS3: 6.1
EPSS Низкий

Описание

Mailcow: dockerized is an open source groupware/email suite based on docker. A Cross-Site Scripting (XSS) vulnerability has been identified within the Quarantine UI of the system. This vulnerability poses a significant threat to administrators who utilize the Quarantine feature. An attacker can send a carefully crafted email containing malicious JavaScript code. This issue has been patched in version 2023-11.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mailcow:mailcow\:_dockerized:*:*:*:*:*:*:*:*
Версия до 2023-11 (исключая)

EPSS

Процентиль: 62%
0.00427
Низкий

8.3 High

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79

EPSS

Процентиль: 62%
0.00427
Низкий

8.3 High

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79