Afterlogic WebMail Pro 8.3.11, and WebMail in Afterlogic Aurora 8.3.11, allows Remote Stored XSS via an attachment name.
References
Link | Resource |
---|---|
https://afterlogic.com | Product |
https://auroramail.wordpress.com/2019/11/25/vulnerability-closed-in-webmail-and-aurora-remote-stored-xss-in-attachments-name/ | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-11-26T15:25:11
Updated: 2019-11-26T15:25:11
Reserved: 2019-11-20T00:00:00
Link: CVE-2019-19129
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-11-26T16:15:13.727
Modified: 2019-12-09T19:33:57.917
Link: CVE-2019-19129
JSON object: View
Redhat Information
No data.
CWE