vendor:
Hivemail Webmail
by:
Shai rod
7,5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: Hivemail Webmail
Affected Version From: 1.41F Build 103
Affected Version To: 1.41F Build 103
Patch Exists: YES
Related CWE: N/A
CPE: hivemail:hivemail_webmail
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Hivemail Webmail Multiple Stored XSS issues
Hivemail Webmail is vulnerable to multiple stored XSS issues. An attacker can send an email to the victim with the payload in the message body, email body (HREF), contacts or calendar. XSS will be triggered when victim opens the message, clicks on the link, view his contacts or view his calendar.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.