Reflected Cross-Site Scripting in Cybozu Mailwise by Cybozu
CVE-2018-0558
6.1MEDIUM
What is CVE-2018-0558?
A reflected cross-site scripting vulnerability exists in Cybozu Mailwise versions 5.0.0 to 5.4.1, enabling remote attackers to execute arbitrary web scripts or HTML code. This is achieved through the exploitation of unspecified vectors in the 'System settings' section, which could lead to session hijacking or unauthorized actions on behalf of users.
Affected Version(s)
Cybozu Mailwise 5.0.0 to 5.4.1