PT-2023-21917 · Openfind · Openfind Mail2000

Published

2023-06-02

·

Updated

2025-12-22

·

CVE-2023-28705

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Openfind Mail2000 (affected versions not specified)
Description The issue arises from insufficient filtering of special characters in email content by the content filtering function. A remote attacker can exploit this by sending phishing emails containing malicious web pages injected with JavaScript, triggering a Reflected Cross-site scripting (XSS) attack when users access the system and open the email.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-28705

Affected Products

Openfind Mail2000