SB2017122015 - Cross-site scripting in Code-Crafters Ability Mail Server
Published: December 20, 2017 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Cross-site scripting (CVE-ID: CVE-2017-17752)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version 4.2.4.
Remediation
Install update from vendor's website.