SB2019031211 - Cross-site scripting in Code-Crafters Ability Mail Server



SB2019031211 - Cross-site scripting in Code-Crafters Ability Mail Server

Published: March 12, 2019 Updated: August 8, 2020

Security Bulletin ID SB2019031211
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Cross-site scripting (CVE-ID: CVE-2019-9557)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe.


Remediation

Install update from vendor's website.