vendor:
MailBee WebMail Pro
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: MailBee WebMail Pro
Affected Version From: 3.4
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:mailbee:webmail_pro:3.4
Platforms Tested:
Unknown
Cross-Site Scripting in MailBee WebMail Pro
The MailBee WebMail Pro application fails to properly sanitize user-supplied input, leading to a cross-site scripting vulnerability. An attacker can exploit this vulnerability to execute arbitrary script code in the browser of an unsuspecting user, potentially stealing authentication credentials and launching further attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to update to the latest version of MailBee WebMail Pro or apply any available patches or security updates.