Cross-Site Scripting Vulnerability in Openfind Mail2000 Webmail
CVE-2019-9763
6.1MEDIUM
What is CVE-2019-9763?
An issue has been identified in Openfind Mail2000 versions 6.0 and 7.0, where an XSS vulnerability can be triggered via an '<object data="data:text/html' substring present in an e-mail message. This flaw could allow attackers to execute arbitrary scripts in the context of the user's session. The vendor has since released patches to mitigate this vulnerability.