Unrated severityNVD Advisory· Published Oct 9, 2011· Updated Apr 29, 2026
CVE-2010-4930
CVE-2010-4930
Description
Cross-site scripting (XSS) vulnerability in index.php in @mail Webmail before 6.2.0 allows remote attackers to inject arbitrary web script or HTML via the MailType parameter in a mail/auth/processlogin action.
Affected products
8cpe:2.3:a:atmail:webmail:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:atmail:webmail:*:*:*:*:*:*:*:*range: <=6.1.9
- cpe:2.3:a:atmail:webmail:6.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:atmail:webmail:6.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:atmail:webmail:6.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:atmail:webmail:6.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:atmail:webmail:6.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:atmail:webmail:6.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:atmail:webmail:6.1.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6News mentions
0No linked articles in our index yet.