PT-2022-23885 · Mdaemon Technologies · Mdaemon Technologies Securitygateway For Email Servers

Published

2022-08-25

·

Updated

2022-08-26

·

CVE-2022-37241

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MDaemon Technologies SecurityGateway for Email Servers version 8.5.2
Description The issue concerns a Cross Site Scripting (XSS) flaw. It can be exploited via the "data leak list ajax" endpoint.
Recommendations For version 8.5.2, consider restricting access to the "data leak list ajax" endpoint until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-37241

Affected Products

Mdaemon Technologies Securitygateway For Email Servers