VYPR

WebMail

by Gecad Technologies

CVEs (4)

  • CVE-2023-48974CriFeb 8, 2024
    risk 0.66cvss 9.6epss 0.03

    Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter.

  • CVE-2024-50601MedNov 11, 2024
    risk 0.40cvss 6.1epss 0.00

    Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute arbitrary Javascript. Exploitation could lead to session hijacking, data leakage, and further exploitation via a…

  • CVE-2023-40355MedFeb 7, 2024
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and…

  • CVE-2024-25080MedApr 1, 2024
    risk 0.31cvss 4.7epss 0.00

    WebMail in Axigen 10.x before 10.3.3.62 allows XSS via the image attachment viewer.