First published: Thu Feb 08 2024(Updated: )
WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mishandling of viewing the usage of SSL certificates.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Axigen Axigen Mobile Webmail | >=10.3.3.0<10.3.3.61 | |
Axigen Axigen Mobile Webmail | >=10.4.0<10.4.24 | |
Axigen Axigen Mobile Webmail | >=10.5.0<10.5.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49101 is classified as a medium severity vulnerability due to its potential for XSS attacks against admin users.
To fix CVE-2023-49101, upgrade your Axigen Mobile Webmail to version 10.3.3.61 or later, 10.4.24 or later, or 10.5.10 or later.
CVE-2023-49101 allows for cross-site scripting (XSS) attacks against administrators through the web interface.
Axigen versions 10.3.x prior to 10.3.3.61, 10.4.x prior to 10.4.24, and 10.5.x prior to 10.5.10 are affected by CVE-2023-49101.
The WebAdmin component of Axigen Mobile Webmail is vulnerable in CVE-2023-49101 due to mishandling of SSL certificate usage viewing.