Cross-Site Scripting Vulnerability in SEPPMail Web Frontend
CVE-2021-31740

6.1MEDIUM

Key Information:

Vendor

Seppmail

Status
Vendor
CVE Published:
30 November 2022

What is CVE-2021-31740?

The SEPPMail web frontend is susceptible to cross-site scripting (XSS) vulnerabilities due to improper handling of user input. This flaw allows attackers to inject malicious scripts into the web page, which can execute in the context of users' browsers. Such attacks could lead to data theft, session hijacking, or other malicious activities, significantly compromising user security.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.