Reflected XSS Vulnerability in weMail (1.14.5)
CVE-2024-43238
7.1HIGH
What is CVE-2024-43238?
The weMail plugin by weDevs contains a vulnerability that allows attackers to exploit improper input neutralization, leading to Reflected Cross-Site Scripting (XSS). This allows malicious scripts to be executed in the context of a user's browser session, which can lead to unauthorized access to sensitive information or compromise user accounts. Users of weMail versions from n/a through 1.14.5 are encouraged to assess their security posture and implement appropriate mitigation strategies.
Affected Version(s)
weMail 0 <= 1.14.5