ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-24133
Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.

Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.

NVD description · AI analysis pending
9.8<1%
  • atmail atmail
CVE-2022-31200
Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms field.

Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms field.

NVD description · AI analysis pending
6.1<1%
  • atmail atmail
CVE-2022-30776
atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.

atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.

NVD description · AI analysis pending
6.14%
  • atmail atmail
CVE-2021-43574
WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI.

WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

NVD description · AI analysis pending
6.12%
  • atmail atmail
CVE-2017-11617
Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML within the body of an

Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML within the body of an email via an IMG element with both single quotes and double quotes.

NVD description · AI analysis pending
6.11% PoC
  • atmail atmail
CVE-2017-9519
+2 in the same advisory: …9518 …9517
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.

atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.

NVD description · AI analysis pending
8.8<1%
  • atmail atmail