CVE-2015-9057: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allow remote attackers to inject arbitrary web script or HTML via multiple parameters, related to /users/index.htm, /quarantine/spam/manage.htm, /quarantine/spam/whitelist.htm, /queues/mail/index/, /system/ssh.htm, /queues/mail/?domain=, and /quarantine/virus/manage.htm.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9057?
CVE-2015-9057 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2015-9057?
To fix CVE-2015-9057, upgrade Proxmox Mail Gateway to version 4.0-8 or later.
What type of vulnerability is CVE-2015-9057?
CVE-2015-9057 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts.
What are the affected parameters in CVE-2015-9057?
CVE-2015-9057 affects multiple parameters in the Proxmox Mail Gateway, including those in /users/index.htm and /quarantine/spam/manage.htm.
Is there a workaround for CVE-2015-9057?
The recommended action for CVE-2015-9057 is to apply the hotfix or upgrade to the latest version, as no effective workaround is specified.