CVE-2018-0559: XSS
Published Jun 26, 2018
·Updated
Cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web script or HTML 'Address' via unspecified vectors.
Affected Software
1 affected component
Cybozu MailWise>=5.0.0<=5.4.1
Event History
Jun 26, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this cross-site scripting vulnerability?
The vulnerability ID for this cross-site scripting vulnerability is CVE-2018-0559.
2
What is the affected software for this vulnerability?
The affected software for this vulnerability is Cybozu Mailwise version 5.0.0 to 5.4.1.
3
How can remote attackers exploit this vulnerability?
Remote attackers can exploit this vulnerability by injecting arbitrary web script or HTML via unspecified vectors in the 'Address' field.
4
What is the severity of CVE-2018-0559?
The severity of CVE-2018-0559 is medium with a CVSS score of 6.1.
5
Is there a fix available for this vulnerability?
Yes, a fix for this vulnerability is available. It is recommended to update Cybozu Mailwise to a version higher than 5.4.1.