Cross-site scripting in Ability Mail Server - CVE-2019-9557
Published: March 12, 2019 / Updated: August 8, 2020
Ability Mail Server
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe.