ZeroHour

CVE-2019-9557

PoC
CVSS 3.0
6.1 medium
EPSS
<1%p60
Published
()
Modified
Description

Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe.

Vendors
codecrafters
Products
ability mail server
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.