PT-2022-23882 · Mdaemon Technologies · Mdaemon Technologies Securitygateway For Email Servers

Published

2022-08-25

·

Updated

2022-08-26

·

CVE-2022-37239

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MDaemon Technologies SecurityGateway for Email Servers version 8.5.2
Description The issue concerns a Cross Site Scripting (XSS) problem. It can be exploited via the "rulles list ajax" API endpoint.
Recommendations For version 8.5.2, consider disabling access to the "rulles list ajax" endpoint until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-37239

Affected Products

Mdaemon Technologies Securitygateway For Email Servers