Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email message with the script in a MIME header name.
| Software | From | Fixed in |
|---|---|---|
| mhonarc / mhonarc | 2.5.12 | 2.5.12.x |
| mhonarc / mhonarc | 2.4.4 | 2.4.4.x |
| mhonarc / mhonarc | 2.5.2 | 2.5.2.x |