CVE-2013-4674: XSS
Cross-site scripting (XSS) vulnerability in the Web Email Protection component in Symantec Encryption Management Server (formerly Symantec PGP Universal Server) before 3.3.0 MP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted encrypted e-mail attachment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4674?
CVE-2013-4674 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2013-4674?
To fix CVE-2013-4674, you should upgrade to Symantec Encryption Management Server version 3.3.0 MP2 or later.
What type of vulnerability is CVE-2013-4674?
CVE-2013-4674 is a cross-site scripting (XSS) vulnerability affecting the Web Email Protection component.
Who is affected by CVE-2013-4674?
CVE-2013-4674 affects users of Symantec Encryption Management Server and Symantec PGP Universal Server versions prior to 3.3.0 MP2.
Can CVE-2013-4674 be exploited remotely?
Yes, CVE-2013-4674 can be exploited by remote authenticated users to inject arbitrary web scripts or HTML.