VYPR
Medium severity6.1NVD Advisory· Published Oct 24, 2018· Updated Jun 17, 2026

CVE-2018-18621

CVE-2018-18621

Description

CommuniGate Pro 6.2 allows stored XSS via a message body in Pronto! Mail Composer, which is mishandled in /MIME/INBOX-MM-1/ if the raw email link (in .txt format) is modified and then renamed with a .html or .wssp extension.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Stalker/Pro2 versions
    cpe:2.3:a:communigate:communigate_pro:6.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:communigate:communigate_pro:6.2:*:*:*:*:*:*:*
    • (no CPE)range: <=6.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.