vendor:
Axigen Mail Server
by:
AmirZargham
6.1
CVSS
MEDIUM
Reflected XSS
79
CWE
Product Name: Axigen Mail Server
Affected Version From: 10.2.3.12
Affected Version To: 10.3.3.47
Patch Exists: YES
Related CWE: CVE-2022-31470
CPE: a:axigen:axigen:10.5.0-4370c946
Platforms Tested: Firefox, Chrome
2023
Axigen < 10.3.3.47, 10.2.3.12 - Reflected XSS
We use the second Reflected XSS to exploit this vulnerability, create a malicious link, and steal user emails.
Mitigation:
Apply the latest patch from the vendor.