WebMail
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-48974 | Cri | 0.66 | 9.6 | 0.03 | Feb 8, 2024 | Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter. | ||
| CVE-2024-50601 | Med | 0.40 | 6.1 | 0.00 | Nov 11, 2024 | Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute arbitrary Javascript. Exploitation could lead to session hijacking, data leakage, and further exploitation via a… | ||
| CVE-2023-40355 | Med | 0.35 | 5.4 | 0.01 | Feb 7, 2024 | Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and… | ||
| CVE-2024-25080 | Med | 0.31 | 4.7 | 0.00 | Apr 1, 2024 | WebMail in Axigen 10.x before 10.3.3.62 allows XSS via the image attachment viewer. |
- risk 0.66cvss 9.6epss 0.03
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter.
- risk 0.40cvss 6.1epss 0.00
Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute arbitrary Javascript. Exploitation could lead to session hijacking, data leakage, and further exploitation via a…
- risk 0.35cvss 5.4epss 0.01
Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and…
- risk 0.31cvss 4.7epss 0.00
WebMail in Axigen 10.x before 10.3.3.62 allows XSS via the image attachment viewer.