vendor:
CommuniGatePro
by:
Boumediene KADDOUR
7.5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: CommuniGatePro
Affected Version From: 6.1.16
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows, Linux, Mac
2017
CommuniGatePro webmails Multiple Stored XSS
Multiple stored XSS vulnerabilities in CommuniGatePro 6.1.16 webmails (crystal, pronto, and pronto4) allow attackers to execute scripts in the victim's browser, gaining control over the victim's mailbox, computer, and ability to send emails on behalf of the victim, deface the victim's mailbox, and invoke malicious code when attachments are sent to the victim.
Mitigation:
To mitigate this vulnerability, it is recommended to implement proper input validation and escaping techniques to prevent untrusted data from being included in web pages. Additionally, keeping software up to date with the latest patches and versions can help prevent exploitation.