ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-9558
Mailtraq WebMail version 2.17.7.3550 has Persistent Cross Site Scripting (XSS) via the body of an e-mail message.

Mailtraq WebMail version 2.17.7.3550 has Persistent Cross Site Scripting (XSS) via the body of an e-mail message. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe.

NVD description · AI analysis pending
6.1<1% PoC
  • mailtraq webmail
CVE-2018-20779
+1 in the same advisory: …20780
Traq 3.7.1 allows SQL Injection via a tickets?search= URI.

Traq 3.7.1 allows SQL Injection via a tickets?search= URI.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • traq traq