CVE-2022-37244: XSS
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37244?
CVE-2022-37244 is a vulnerability in MDaemon Technologies SecurityGateway for Email Servers 8.5.2 that allows IFRAME injection via the currentRequest parameter.
How can the IFRAME Injection vulnerability be exploited?
The IFRAME Injection vulnerability in MDaemon Technologies SecurityGateway for Email Servers 8.5.2 can be exploited by injecting a malicious tag via the currentRequest parameter after login.
What is the severity rating of CVE-2022-37244?
CVE-2022-37244 has a severity rating of medium with a CVSS score of 5.4.
What software versions are affected by CVE-2022-37244?
CVE-2022-37244 affects MDaemon Technologies SecurityGateway for Email Servers version 8.5.2.
How can I fix the IFRAME Injection vulnerability in MDaemon Technologies SecurityGateway for Email Servers 8.5.2?
To fix the IFRAME Injection vulnerability, update MDaemon Technologies SecurityGateway for Email Servers to a version that is not affected by the vulnerability.