PT-2018-4051 · Apache · Hupa Webmail

Publicado

2018-02-27

·

Atualizado

2022-05-14

·

CVE-2012-3536

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hupa Webmail application from the Apache James project versions prior to 0.0.3
Description The issue concerns two XSS vulnerabilities in the message list and view of the Hupa Webmail application. An attacker could exploit this by sending a carefully crafted email to a user, which would trigger the XSS when the email was opened or when a list of messages were viewed.
Recommendations For versions prior to 0.0.3, update to version 0.0.3 to resolve the issue.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-3536
GHSA-7CRP-P2VC-69R7

Produtos afetados

Hupa Webmail