VYPR
Medium severity6.1NVD Advisory· Published Nov 27, 2020· Updated Jun 17, 2026

CVE-2020-29133

CVE-2020-29133

Description

jsp/upload.jsp in Coremail XT 5.0 allows XSS via an uploaded personal signature, as demonstrated by a .jpg.html filename in the signImgFile parameter.

Affected products

3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.