Vulnerabilities
8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-24133 | Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page. Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2022-31200 | Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms field. Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms field. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2022-30776 | atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter. atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter. NVD description · AI analysis pending | 6.1 | 4% |
| — | ||
| CVE-2021-43574 | WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI. WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI. NOTE: This vulnerability only affects products that are no longer supported by the maintainer NVD description · AI analysis pending | 6.1 | 2% |
| — | ||
| CVE-2017-11617 | Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML within the body of an Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML within the body of an email via an IMG element with both single quotes and double quotes. NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — | |
| CVE-2017-9519 | atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account. atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account. NVD description · AI analysis pending | 8.8 | <1% |
| — |