vendor:
Postie
by:
loneferret
7,5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: Postie
Affected Version From: 1.4.3
Affected Version To: 1.4.3
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:postie
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu Server LAMP 8.04, MAC OS Lion
2012
Postie 1.4.3 XSS Vulnerability
A Cross-Site Scripting (XSS) vulnerability was discovered in Postie 1.4.3. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'From' field of an email. An attacker can exploit this vulnerability by sending a malicious email with a specially crafted payload to a victim. The payload will be executed in the victim's browser when the victim views the email.
Mitigation:
Upgrade to the latest version of Postie.