296,362
Total vulnerabilities in the database
Cross-site scripting (XSS) vulnerability in the Webmail interface for IceWarp Merak Mail Server before 9.0.0 allows remote attackers to inject arbitrary JavaScript via a javascript: URI in an attribute of an element in an email message body, as demonstrated by the onload attribute in a BODY element.
Software | From | Fixed in |
---|---|---|
icewarp / merak_mail_server | 8.9.1 | 8.9.1.x |
icewarp / merak_mail_server | 8.9.2 | 8.9.2.x |