First published: Wed Jul 31 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the Web Email Protection component in Symantec Encryption Management Server (formerly Symantec PGP Universal Server) before 3.3.0 MP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted encrypted e-mail attachment.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Encryption Management Server | <=3.3.0 | |
Symantec Encryption Management Server | =3.3.0 | |
Symantec PGP Universal Server | =3.2.0 | |
Symantec PGP Universal Server | =3.2.1 | |
Symantec PGP Universal Server | =3.2.1-mp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4674 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2013-4674, you should upgrade to Symantec Encryption Management Server version 3.3.0 MP2 or later.
CVE-2013-4674 is a cross-site scripting (XSS) vulnerability affecting the Web Email Protection component.
CVE-2013-4674 affects users of Symantec Encryption Management Server and Symantec PGP Universal Server versions prior to 3.3.0 MP2.
Yes, CVE-2013-4674 can be exploited by remote authenticated users to inject arbitrary web scripts or HTML.