Описание
Mailcow: dockerized is an open source groupware/email suite based on docker. A Cross-Site Scripting (XSS) vulnerability has been identified within the Quarantine UI of the system. This vulnerability poses a significant threat to administrators who utilize the Quarantine feature. An attacker can send a carefully crafted email containing malicious JavaScript code. This issue has been patched in version 2023-11.
Ссылки
- Release Notes
- Vendor Advisory
- Release Notes
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2023-11 (исключая)
cpe:2.3:a:mailcow:mailcow\:_dockerized:*:*:*:*:*:*:*:*
EPSS
Процентиль: 62%
0.00427
Низкий
8.3 High
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79
EPSS
Процентиль: 62%
0.00427
Низкий
8.3 High
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79