CVE-2023-22902: XSS
Published Mar 27, 2023
·Updated
Openfind Mail2000 file uploading function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can exploit this vulnerability to inject JavaScript, conducting an XSS attack.
Affected Software
2 affected components
Openfind Mail2000=7.0
Openfind Mail2000=8.0
Event History
Mar 27, 2023
CVE Published
04:15 AM
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-22902.
2
What software is affected by this vulnerability?
Openfind Mail2000 versions 7.0 and 8.0 are affected by this vulnerability.
3
What is the severity of CVE-2023-22902?
The severity of CVE-2023-22902 is medium with a CVSS score of 5.4.
4
How can an authenticated remote attacker exploit this vulnerability?
An authenticated remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and conduct an XSS attack.
5
Is there a fix available for this vulnerability?
The reference link provided may have information on available fixes for this vulnerability.