vendor:
Atmail Webmail
by:
Smash_ & Brag
8,8
CVSS
HIGH
Cross Site Scripting, Full Path Disclosure, Persistent XSS
79, 200, 79
CWE
Product Name: Atmail Webmail
Affected Version From: 7.2
Affected Version To: 7.1.1
Patch Exists: YES
Related CWE: N/A
CPE: atmail.com
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Web
2014
Atmail Webmail =>7.2 – Multiple XSS & FPD
Atmail Webmail versions 7.2 and below are vulnerable to multiple XSS and FPD. The XSS vulnerabilities can be exploited by sending a malicious request to the server. The FPD vulnerability can be exploited by sending a GET request to the server. The Persistent XSS vulnerability can be exploited by sending a GET request to the server.
Mitigation:
Upgrade to the latest version of Atmail Webmail, disable unnecessary features, and use a web application firewall.