SB2019031211 - Cross-site scripting in Code-Crafters Ability Mail Server
Published: March 12, 2019 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Cross-site scripting (CVE-ID: CVE-2019-9557)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe.
Remediation
Install update from vendor's website.