CVE-2015-9279: XSS
Published Jan 16, 2019
·Updated
MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.
Affected Software
1 affected component
MailEnable MailEnable<8.60
Event History
Jan 16, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9279?
CVE-2015-9279 has been classified as a medium severity vulnerability due to its potential for exploitation via stored XSS attacks.
2
How do I fix CVE-2015-9279?
To fix CVE-2015-9279, upgrade to MailEnable version 8.60 or later which addresses this vulnerability.
3
What type of vulnerability is CVE-2015-9279?
CVE-2015-9279 is a stored cross-site scripting (XSS) vulnerability that can be exploited through malformed email content.
4
What are the potential impacts of CVE-2015-9279?
The potential impacts of CVE-2015-9279 include unauthorized actions on behalf of users, data theft, and compromising session integrity.
5
In which versions of MailEnable is CVE-2015-9279 present?
CVE-2015-9279 is present in all versions of MailEnable prior to 8.60.