CVE-2024-28063: XSS
Published May 18, 2024
·Updated
Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.
Affected Software
2 affected components
Kiteworks Totemomail<=7.0.0
Totemo Totemomail<=7.0.0
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 18, 2024
CVE Published
via NVD·10:15 PM
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 2, 2024
Data Sourced
via MITRE·12:54 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-28063?
CVE-2024-28063 is classified as a medium severity vulnerability.
2
How do I fix CVE-2024-28063?
To fix CVE-2024-28063, upgrade Kiteworks Totemomail to version 7.0.1 or later.
3
What does CVE-2024-28063 affect?
CVE-2024-28063 affects Kiteworks Totemomail versions up to and including 7.0.0.
4
What type of vulnerability is CVE-2024-28063?
CVE-2024-28063 is a reflected cross-site scripting (XSS) vulnerability.
5
Can CVE-2024-28063 lead to data breaches?
Yes, CVE-2024-28063 can potentially lead to data breaches through exploitation of the reflected XSS.