vendor:
SquirrelMail
by:
Unknown
7.5
CVSS
HIGH
Email header HTML injection
79
CWE
Product Name: SquirrelMail
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE:
CPE: a:squirrelmail:squirrelmail
Platforms Tested:
Unknown
SquirrelMail Email Header HTML Injection Vulnerability
SquirrelMail is reported to be prone to an email header HTML injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied email header strings. An attacker can exploit this issue to gain access to an unsuspecting user's cookie-based authentication credentials; disclosure of personal email is possible. Other attacks are also possible.
Mitigation:
To mitigate this vulnerability, it is recommended to update to the latest version of SquirrelMail that addresses this issue. Additionally, users should exercise caution when opening emails from untrusted sources.