CVE-2015-6942: XSS
Cross-site scripting (XSS) vulnerability in Coremail XT3.0 allows remote attackers to inject arbitrary web script or HTML via a hyperlink in a document attachment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6942?
CVE-2015-6942 is considered a high severity vulnerability due to its potential for allowing remote attackers to execute arbitrary scripts.
How do I fix CVE-2015-6942?
To fix CVE-2015-6942, it is recommended to update Coremail XT to the latest patched version that addresses this vulnerability.
What does CVE-2015-6942 allow attackers to do?
CVE-2015-6942 allows remote attackers to inject arbitrary web scripts or HTML through malicious hyperlinks in document attachments.
Which software versions are affected by CVE-2015-6942?
CVE-2015-6942 specifically affects Coremail XT version 3.0.
Is there a workaround for CVE-2015-6942 until I can apply a patch?
A potential workaround for CVE-2015-6942 is to restrict the ability to upload document attachments or to sanitize input to prevent XSS.