CVE-2022-29976: XSS
Published May 11, 2022
·Updated
An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 .
Affected Software
1 affected component
Altn Mdaemon<22.0.0
Event History
May 11, 2022
CVE Published
via MITRE·12:54 PM
Data Sourced
via MITRE·12:54 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-29976.
2
What is the severity of CVE-2022-29976?
The severity of CVE-2022-29976 is medium with a CVSS score of 5.4.
3
How can an attacker exploit CVE-2022-29976?
An attacker can exploit CVE-2022-29976 by sending a specially crafted request containing malicious script code to the BCC parameter in MDaemon before version 22.0.0, which will be executed by the victim's browser.
4
Is authentication required to exploit CVE-2022-29976?
Yes, authentication is required to exploit CVE-2022-29976.
5
How can I fix the vulnerability?
To fix the vulnerability, update MDaemon to version 22.0.0 or higher, as the vulnerability has been patched in that version.