vendor:
T-dah Webmail Client
by:
loneferret of Offensive Security
7.5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: T-dah Webmail Client
Affected Version From: 3.2.2000
Affected Version To: 2.3
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Ubuntu Server LAMP 11.10, Windows 7 Pro (x86) SP1
2012
T-dah Webmail Client XSS Vulnerability
The T-dah Webmail Client version 3.2.0-2.3 is vulnerable to XSS attacks. An attacker can inject malicious scripts into the body of an email, which will be executed when the email is viewed by the victim. This can lead to session hijacking, defacement of the webmail interface, and stealing of sensitive information.
Mitigation:
Upgrade to a patched version of T-dah Webmail Client. Avoid clicking on suspicious links or opening emails from unknown senders.