CVE-2018-14950: XSS
Published Aug 5, 2018
·Updated
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack.
Affected Software
1 affected component
Squirrelmail Squirrelmail<=1.4.22
Remediation
Patch Available
Event History
Aug 5, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-14950?
CVE-2018-14950 has a high severity rating due to its ability to execute cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-14950?
To fix CVE-2018-14950, users should upgrade to a version of SquirrelMail later than 1.4.22.
3
What impact does CVE-2018-14950 have on SquirrelMail?
CVE-2018-14950 allows attackers to inject malicious scripts into user sessions, potentially compromising user data.
4
Which versions of SquirrelMail are affected by CVE-2018-14950?
CVE-2018-14950 affects all versions of SquirrelMail up to and including 1.4.22.
5
Is CVE-2018-14950 a client-side or server-side vulnerability?
CVE-2018-14950 is primarily a client-side vulnerability as it exploits the way web browsers handle XSS attacks.