Openfind Mail2000 - XSS (Reflected Cross-site scripting)
CVE-2023-28705

6.1MEDIUM

Key Information:

Vendor
Openfind
Status
Vendor
CVE Published:
2 June 2023

Summary

Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. A remote attacker can exploit this vulnerability using phishing emails that contain malicious web pages injected with JavaScript. When users access the system and open the email, it triggers an XSS (Reflected Cross-site scripting) attack.

Affected Version(s)

Mail2000 <= 7

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.