CVE-2014-2325: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway before 3.1-5829 allow remote attackers to inject arbitrary web script or HTML via the (1) state parameter to objects/who/index.htm or (2) User email address to quarantine/spam/manage.htm.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2325?
CVE-2014-2325 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2014-2325?
To fix CVE-2014-2325, upgrade to Proxmox Mail Gateway version 3.1-5829 or later.
What types of attacks can CVE-2014-2325 enable?
CVE-2014-2325 can enable remote attackers to execute arbitrary web scripts or HTML in the user's browser.
Which versions of Proxmox Mail Gateway are affected by CVE-2014-2325?
Proxmox Mail Gateway versions up to 3.1-5741, 3.0, 3.1, 3.1-5670, and 3.1-5673 are affected by CVE-2014-2325.
Can CVE-2014-2325 be exploited without user interaction?
Yes, CVE-2014-2325 can be exploited without user interaction, making it a significant security risk.