First published: Thu Feb 08 2024(Updated: )
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter.
Credit: cve@mitre.org Vincent McRae, Mesut Cetin
Affected Software | Affected Version | How to fix |
---|---|---|
Axigen Mail Server for Windows | <=10.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48974 is classified as a moderate severity Cross Site Scripting vulnerability.
To fix CVE-2023-48974, upgrade Axigen WebMail to version 10.3.3.61 or later.
CVE-2023-48974 affects Axigen Mail Server versions up to and including 10.5.7.
An attacker exploiting CVE-2023-48974 can escalate privileges by inserting a crafted script into the serverName_input parameter.
The impact of CVE-2023-48974 includes potential unauthorized access and control over affected Axigen WebMail installations.