vendor:
Ability Mail Server
by:
Aloyce J. Makalanga
6,1
CVSS
MEDIUM
Persistent Cross Site Scripting (XSS)
79
CWE
Product Name: Ability Mail Server
Affected Version From: 3.3.2
Affected Version To: 3.3.2
Patch Exists: YES
Related CWE: CVE-2017-17752
CPE: a:codecrafters:ability_mail_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
Ability Mail Server 3.3.2 Persistent Cross Site Scripting (XSS)
Ability Mail Server 3.3.2 has Persistent Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email.
Mitigation:
Update to version 4.2.4