CVE-2013-2585: XSS
Cross-site scripting (XSS) vulnerability in Atmail Webmail Server 6.6.x before 6.6.3 and 7.0.x before 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the PATHINFO to index.php/mail/viewmessage/getattachment/folder/INBOX/uniqueId/<MessageID>/filenameOriginal/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2585?
CVE-2013-2585 is classified as a medium severity vulnerability due to its impact on the web application's security.
How do I fix CVE-2013-2585?
To fix CVE-2013-2585, upgrade Atmail Webmail Server to version 6.6.3 or 7.0.3 or later.
What is the impact of CVE-2013-2585?
The impact of CVE-2013-2585 allows attackers to inject arbitrary web script or HTML into the application, leading to potential data theft or session hijacking.
Which versions of Atmail are affected by CVE-2013-2585?
CVE-2013-2585 affects Atmail Webmail Server versions 6.6.0 through 6.6.2 and 7.0.0 through 7.0.1.
Is there a workaround for CVE-2013-2585?
There is no known workaround for CVE-2013-2585; upgrading to a patched version is recommended.