CVE-2018-0557: XSS
Published Jun 26, 2018
·Updated
Stored cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web script or HTML 'E-mail Details Screen' via unspecified vectors.
Affected Software
1 affected component
Cybozu MailWise>=5.0.0<=5.4.1
Event History
Jun 26, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-0557.
2
What is the severity of CVE-2018-0557?
The severity of CVE-2018-0557 is medium (6.1).
3
What is the affected software?
The affected software is Cybozu Mailwise version 5.0.0 to 5.4.1.
4
How can remote attackers exploit CVE-2018-0557?
Remote attackers can exploit CVE-2018-0557 by injecting arbitrary web script or HTML in the 'E-mail Details Screen'.
5
Is there a fix available for CVE-2018-0557?
Yes, a fix is available for CVE-2018-0557. Please refer to the vendor's support website for more information.