Cross-site scripting (XSS) vulnerability in add.php in Address Add Plugin 1.9 and 2.0 for Squirrelmail allows remote attackers to inject arbitrary web script or HTML via the IMG tag.
Software | From | Fixed in |
---|---|---|
squirrelmail / address_add_plugin | 1.9 | 1.9.x |
squirrelmail / address_add_plugin | 2.0 | 2.0.x |