go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Openfind Mail2000 - XSS (Reflected Cross-site scripting)

TVN ID TVN-202306001
CVE ID CVE-2023-28705
CVSS 5.4 (Medium)
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected Products Openfind Mail2000 <= V7
Description Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. A remote attacker can exploit this vulnerability using phishing emails that contain malicious web pages injected with JavaScript. When users access the system and open the email, it triggers an XSS (Reflected Cross-site scripting) attack.
Solution Update Openfind Mail2000 version to V8
Credit Naional Institute for Cyber Security
Public Date 2023-06-16
Top