CVE-2015-4657: XSS
Published Jun 18, 2015
·Updated
Cross-site scripting (XSS) vulnerability in Mailbird 2.0.16.0 and earlier allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with a crafted URL.
Affected Software
1 affected component
Mailbird Mailbird<=2.0.16.0
Event History
Jun 18, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4657?
The severity of CVE-2015-4657 is considered to be medium, as it allows for cross-site scripting attacks affecting user sessions.
2
How do I fix CVE-2015-4657?
To fix CVE-2015-4657, upgrade Mailbird to version 2.0.17.0 or later which addresses the vulnerability.
3
Who is affected by CVE-2015-4657?
Users of Mailbird versions 2.0.16.0 and earlier are affected by CVE-2015-4657.
4
What types of attacks can be performed using CVE-2015-4657?
CVE-2015-4657 can be exploited to execute arbitrary scripts or HTML code in a user's web browser, compromising session data.
5
Is CVE-2015-4657 a common vulnerability?
CVE-2015-4657 is a relatively common cross-site scripting vulnerability, often found in email clients and web applications.