PT-2022-23881 · Mdaemon Technologies · Mdaemon Technologies Securitygateway For Email Servers

Published

2022-08-25

·

Updated

2022-08-27

·

CVE-2022-37238

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MDaemon Technologies SecurityGateway for Email Servers version 8.5.2
Description The issue is related to Cross Site Scripting (XSS) and can be exploited via the currentRequest parameter. This allows for malicious scripts to be injected into otherwise trusted websites, potentially leading to unauthorized access or control of user sessions.
Recommendations For MDaemon Technologies SecurityGateway for Email Servers version 8.5.2, consider restricting access to the currentRequest parameter to minimize the risk of exploitation until a patch is available. Avoid using the currentRequest parameter in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-37238

Affected Products

Mdaemon Technologies Securitygateway For Email Servers