First published: Tue Jun 26 2018(Updated: )
Stored cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web script or HTML 'E-mail Details Screen' via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Mailwise | >=5.0.0<=5.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-0557.
The severity of CVE-2018-0557 is medium (6.1).
The affected software is Cybozu Mailwise version 5.0.0 to 5.4.1.
Remote attackers can exploit CVE-2018-0557 by injecting arbitrary web script or HTML in the 'E-mail Details Screen'.
Yes, a fix is available for CVE-2018-0557. Please refer to the vendor's support website for more information.