vendor:
Axigen Mail Server
by:
loneferret
7,5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: Axigen Mail Server
Affected Version From: 8.0.1
Affected Version To: 8.0.1
Patch Exists: NO
Related CWE: N/A
CPE: a:axigen:axigen_mail_server:8.0.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012
Axigen Mail Server 8.0.1 XSS Vulnerability
Axigen Mail Server 8.0.1 is vulnerable to Cross-Site Scripting (XSS) attacks. An attacker can inject malicious JavaScript code into the body of an email message, which will be executed when the message is viewed by the victim. The malicious code can be used to steal session cookies, redirect the victim to malicious websites, or perform other malicious actions.
Mitigation:
Input validation should be used to prevent malicious code from being injected into the body of an email message.