vendor:
Campus Pipeline
by:
Unknown
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: Campus Pipeline
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unknown
Unknown
Campus Pipeline Remote Email Attachment Script Injection Vulnerability
The vulnerability allows remote attackers to inject and execute arbitrary script code through email attachments in Campus Pipeline. By manipulating the victim's email account, an attacker can potentially gain control of the account and steal authentication credentials. The issue is caused by the application's failure to properly sanitize user-supplied HTML and script code in email documents.
Mitigation:
Unknown