CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
AI Score
Confidence
High
EPSS
Percentile
81.4%
Cross-site scripting (XSS) vulnerability in the Webmail interface for IceWarp Merak Mail Server before 9.0.0 allows remote attackers to inject arbitrary JavaScript via a javascript: URI in an attribute of an element in an email message body, as demonstrated by the onload attribute in a BODY element.
Vendor | Product | Version | CPE |
---|---|---|---|
icewarp | merak_mail_server | 8.9.1 | cpe:2.3:a:icewarp:merak_mail_server:8.9.1:*:*:*:*:*:*:* |
icewarp | merak_mail_server | 8.9.2 | cpe:2.3:a:icewarp:merak_mail_server:8.9.2:*:*:*:*:*:*:* |