vendor:
@Mail
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: @Mail
Affected Version From: 6.1.2009
Affected Version To: 6.1.2009
Patch Exists: NO
Related CWE:
CPE: a:atmailwebmail:atmail:6.1.9
Platforms Tested: Unknown
Unknown
Cross-Site Scripting vulnerability in @Mail
The @Mail application fails to properly sanitize user-supplied data, allowing an attacker to execute arbitrary JavaScript code in the browser of a targeted user. This can lead to the theft of sensitive information such as authentication credentials and enable further attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the @Mail application.