vendor:
WebMail Pro
by:
Sébastien Duquette and Gardien Virtuel
7.5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: WebMail Pro
Affected Version From: 4.7.10
Affected Version To: 4.7.10
Patch Exists: YES
Related CWE: N/A
CPE: afterlogic:webmail_pro
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Firefox 3.5 and Internet Explorer 8
2009
Cross-Site Scripting flaw in AfterLogic WebMail Pro
AfterLogic WebMail Pro is vulnerable to Cross-Site Scripting, allowing injection of malicious code in the context of the application. The targeted user must be logged in the webmail. This proof of concept was successfully tested in Firefox 3.5 and Internet Explorer 8.
Mitigation:
Update to AfterLogic Webmail Pro 4.7.11 or later.