Summary
AfterLogic WebMail Pro is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie- based authentication credentials
other attacks are also possible.
AfterLogic WebMail Pro 4.7.10 and prior versions are affected.
Solution
Reports indicate that the vendor addressed these issues in WebMail Pro 4.7.11, but Symantec has not confirmed this. Please contact the vendor for more information.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2009-4743 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities
- 2532|Gigs Directory Traversal And SQL Injection Multiple Vulnerabilities
- Afian 'includer.php' Directory Traversal Vulnerability
- Advanced Image Hosting Cross Site Scripting Vulnerability
- Apache ActiveMQ 'Cron Jobs' Cross Site Scripting Vulnerability
- Aardvark Topsites PHP 'index.php' Multiple Cross Site Scripting Vulnerabilities