CVE-2007-5046: XSS
Cross-site scripting (XSS) vulnerability in the Webmail interface for IceWarp Merak Mail Server before 9.0.0 allows remote attackers to inject arbitrary JavaScript via a javascript: URI in an attribute of an element in an email message body, as demonstrated by the onload attribute in a BODY element.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5046?
CVE-2007-5046 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2007-5046?
To fix CVE-2007-5046, upgrade your IceWarp Merak Mail Server to version 9.0.0 or later.
Which versions of IceWarp Merak Mail Server are affected by CVE-2007-5046?
IceWarp Merak Mail Server versions 8.9.1 and 8.9.2 are affected by CVE-2007-5046.
What types of attacks can be executed due to CVE-2007-5046?
CVE-2007-5046 allows remote attackers to inject arbitrary JavaScript, potentially executing malicious scripts in users' browsers.
Can CVE-2007-5046 be exploited via email?
Yes, CVE-2007-5046 can be exploited through email messages that include crafted JavaScript in the body.