CVE-2021-31739: XSS
The SEPPmail solution is vulnerable to a Cross-Site Scripting vulnerability (XSS), because user input is not correctly encoded in HTML attributes when returned by the server.SEPPmail 11.1.10 allows XSS via a recipient address.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-31739?
CVE-2021-31739 is a Cross-Site Scripting (XSS) vulnerability found in the SEPPmail solution.
How does CVE-2021-31739 impact SEPPmail?
CVE-2021-31739 allows attackers to execute malicious scripts in the context of SEPPmail, potentially leading to unauthorized actions or data theft.
What is the severity of CVE-2021-31739?
CVE-2021-31739 has a severity value of 6.1, which is considered medium.
How can I fix CVE-2021-31739?
To fix CVE-2021-31739, it is recommended to update the SEPPmail solution to version 11.1.11 or later, which addresses the Cross-Site Scripting vulnerability.
Where can I find more information about CVE-2021-31739?
You can find more information about CVE-2021-31739 in the following reference: https://www.pentagrid.ch/en/blog/multiple-vulnerabilities-in-seppmail/