vendor:
MailPost
by:
Unknown
7.5
CVSS
HIGH
Cross-site scripting
79
CWE
Product Name: MailPost
Affected Version From: MailPost 5.1.1sv
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:mailpost:mailpost:5.1.1sv
Platforms Tested: Unknown
Unknown
Cross-site scripting vulnerability in MailPost
The vulnerability in MailPost allows an attacker to execute arbitrary HTML and script code in a user's browser through a malicious error message. This can lead to the theft of cookie-based authentication credentials or other attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user-supplied data before displaying it to users.