CVE-2021-43574: XSS
Published Nov 15, 2021
·Updated
UNSUPPORTED WHEN ASSIGNED WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
1 affected component
Atmail atmail=6.5.0
Event History
Nov 15, 2021
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-43574.
2
What is the severity of CVE-2021-43574?
The severity of CVE-2021-43574 is medium with a CVSS score of 6.1.
3
How does CVE-2021-43574 affect Atmail?
CVE-2021-43574 affects Atmail version 6.5.0, a version released in 2012.
4
What is the impact of CVE-2021-43574?
CVE-2021-43574 allows XSS (cross-site scripting) attacks via the format parameter in the WebAdmin Control Panel.
5
Are there any fixes or mitigation steps available for CVE-2021-43574?
As this vulnerability affects a version that is no longer supported by the maintainer, it is recommended to upgrade to a supported version or consider an alternative solution.