First published: Wed Feb 07 2024(Updated: )
Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and Ajax versions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Axigen Mobile Webmail | >=10.3.3.0<10.3.3.59 | |
Axigen Mobile Webmail | >=10.4.0<10.4.19 | |
Axigen Mobile Webmail | >=10.5.0<10.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40355 is considered a critical Cross Site Scripting (XSS) vulnerability.
To mitigate CVE-2023-40355, users should update Axigen Mobile Webmail to versions 10.3.3.59, 10.4.19, or 10.5.5 or later.
CVE-2023-40355 can allow authenticated attackers to execute arbitrary code and obtain sensitive information.
Affected Axigen versions include 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5.
Authenticated users of Axigen Mobile Webmail versions prior to the patched releases are at risk for CVE-2023-40355.