CVE-2022-30776: XSS
Published May 16, 2022
·Updated
atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.
Affected Software
1 affected component
Atmail atmail=6.5.0
Event History
May 16, 2022
CVE Published
via MITRE·01:35 PM
Data Sourced
via MITRE·01:35 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this atmail vulnerability?
The vulnerability ID of this atmail vulnerability is CVE-2022-30776.
2
What is the title of this atmail vulnerability?
The title of this atmail vulnerability is 'atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.'
3
What is the severity level of CVE-2022-30776?
The severity level of CVE-2022-30776 is medium.
4
How does the vulnerability in atmail 6.5.0 occur?
The vulnerability in atmail 6.5.0 occurs when an attacker is able to inject malicious scripts into the 'error' parameter of the 'index.php/admin/index/' page, leading to cross-site scripting (XSS) attacks.
5
Is there a fix available for this atmail vulnerability?
Yes, there is a fix available for this atmail vulnerability. It is recommended to update to a version of atmail that is not affected by this vulnerability.