PT-2022-20748 · Axigen · Axigen Mobile Webmail

Published

2022-06-07

·

Updated

2023-09-09

·

CVE-2022-31470

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Axigen Mobile WebMail versions prior to 10.2.3.12 Axigen Mobile WebMail versions 10.3.x prior to 10.3.3.47
Description The issue allows attackers to run arbitrary Javascript code, using an active end-user session for a logged-in user, to access and retrieve mailbox content. This is due to an XSS vulnerability in the index mobile changepass.hsp reset-password section.
Recommendations For versions prior to 10.2.3.12, update to version 10.2.3.12 or later. For versions 10.3.x prior to 10.3.3.47, update to version 10.3.3.47 or later. As a temporary workaround, consider restricting access to the index mobile changepass.hsp reset-password section until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-31470

Affected Products

Axigen Mobile Webmail