Atmail · Atmail · CVE-2017-11617
**Name of the Vulnerable Software and Affected Versions**
atmail versions prior to 7.8.0.2
**Description**
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML within the body of an email via an IMG element with both single quotes and double quotes.
**Recommendations**
For versions prior to 7.8.0.2, update to version 7.8.0.2 or later to resolve the issue.