Medium severity6.1NVD Advisory· Published Feb 27, 2018· Updated Jun 16, 2026
CVE-2012-3536
CVE-2012-3536
Description
Two XSS vulnerabilities were fixed in message list and view in the Hupa Webmail application from the Apache James project. An attacker could send a carefully crafted email to a user of Hupa which would trigger a XSS when the email was opened or when a list of messages were viewed. This issue was addressed in Hupa 0.0.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.james.hupa:hupa-parentMaven | < 0.0.3 | 0.0.3 |
Affected products
3Patches
Vulnerability mechanics
References
5- svn.apache.org/viewvcnvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-7crp-p2vc-69r7ghsaADVISORY
- james.apache.org/hupa/index.htmlnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2012-3536ghsaADVISORY
- github.com/apache/james-hupa/commit/aff28a8117a49969b0fc8cc9926c19fa90146d8dghsaWEB
News mentions
0No linked articles in our index yet.