PT-2018-12831 · Squirrelmail · Squirrelmail

Salvatore Bonaccorso

·

Publicado

2018-08-05

·

Atualizado

2019-08-15

·

CVE-2018-14955

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SquirrelMail versions prior to 1.4.23
Description The issue concerns the mail message display page in SquirrelMail, where an XSS attack can be performed using SVG animations, specifically by manipulating the animate attribute to execute malicious code.
Recommendations For SquirrelMail versions prior to 1.4.23, update to version 1.4.23 or later to resolve the issue.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-14955
DLA-1484-1

Produtos afetados

Squirrelmail