vendor:
SqWebMail
by:
Unknown
5.5
CVSS
MEDIUM
HTML Injection
79
CWE
Product Name: SqWebMail
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
SqWebMail Email Header HTML Injection Vulnerability
An email header HTML injection vulnerability exists in SqWebMail due to improper sanitization of user-supplied email header strings. This allows an attacker to inject malicious HTML and script code into email headers, potentially leading to the exploitation of an unsuspecting user's cookie-based authentication credentials.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user-supplied input to prevent the injection of malicious HTML and script code. Additionally, users should exercise caution when viewing email messages from unknown or untrusted sources.