PT-2023-31045 · Mailcow · Mailcow

Derlinkman

·

Publicado

2023-11-30

·

Atualizado

2023-12-05

·

CVE-2023-49077

CVSS v3.1

8.3

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Mailcow: dockerized versions prior to 2023-11
Description A Cross-Site Scripting (XSS) issue has been identified within the Quarantine UI of the system, posing a significant threat to administrators who utilize the Quarantine feature. An attacker can send a carefully crafted email containing malicious JavaScript code.
Recommendations For versions prior to 2023-11, update to version 2023-11 to resolve the issue. As a temporary workaround, consider restricting access to the Quarantine UI to minimize the risk of exploitation. Avoid using the Quarantine feature until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-49077
GHSA-46X4-W2FM-5X6G

Produtos afetados

Mailcow