vendor:
Mailsuite Pro
by:
loneferret of Offensive Security
5.5
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: Mailsuite Pro
Affected Version From: 6.3
Affected Version To: 6.3
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows Server 2003 SP2, Windows 7 Pro SP1 (x86), Windows XP Pro SP3 (x86), MAC OS Lion
2012
AfterLogic Mailsuite Pro XSS Vulnerability
This exploit allows an attacker to inject malicious scripts into the body of an email sent using AfterLogic Mailsuite Pro. The payload can be used to execute arbitrary JavaScript code in the victim's browser.
Mitigation:
The vendor has not provided a patch for this vulnerability. To mitigate the risk, users are advised to avoid opening emails from untrusted sources or enabling HTML rendering in emails.