PT-2020-12814 · Cybersolutions · Cybermail

Tony Kuo

·

Published

2020-04-13

·

Updated

2020-04-13

·

CVE-2020-11734

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CyberSolutions CyberMail versions 5.0 and later
Description The issue allows for cross-site scripting (XSS) via the ACTION parameter in the /cgi-bin/go endpoint. This could potentially lead to malicious script execution on the client-side.
Recommendations For CyberSolutions CyberMail versions 5.0 and later, consider restricting access to the /cgi-bin/go endpoint until a patch is available. As a temporary workaround, avoid using the ACTION parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11734

Affected Products

Cybermail