PT-2022-23888 · Mdaemon Technologies · Mdaemon Securitygateway For Email Servers

Published

2022-08-25

·

Updated

2022-08-29

·

CVE-2022-37244

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MDaemon Technologies SecurityGateway for Email Servers version 8.5.2
Description The issue allows for IFRAME Injection via the currentRequest parameter after login, which can lead to the injection of malicious tags, resulting in IFRAME injection.
Recommendations For version 8.5.2, avoid using the currentRequest parameter in affected areas until a fix is available. As a temporary workaround, consider restricting access to the parameter currentRequest to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-37244

Affected Products

Mdaemon Securitygateway For Email Servers