First published: Mon Nov 18 2019(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Mailbird before 2.7.5.0 r allow remote attackers to execute arbitrary JavaScript in a privileged context via a crafted HTML mail message. This vulnerability is distinct from CVE-2015-4657.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Getmailbird Mailbird | <2.7.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15054 is a vulnerability in Mailbird before version 2.7.5.0 that allows remote attackers to execute arbitrary JavaScript in a privileged context through a crafted HTML mail message.
CVE-2019-15054 has a severity rating of 6.1 (medium).
CVE-2019-15054 affects Mailbird versions up to but excluding 2.7.5.0.
To fix CVE-2019-15054, update Mailbird to version 2.7.5.0 or later.
You can find more information about CVE-2019-15054 at the following references: [https://startrekdude.github.io/mailbird.html](https://startrekdude.github.io/mailbird.html) and [https://www.getmailbird.com/ReleaseNotes/LatestReleaseNotes.html](https://www.getmailbird.com/ReleaseNotes/LatestReleaseNotes.html)