Open WebMail is prone to a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input. The problem presents itself when malicious HTML and script code is sent to the application through the 'logindomain' parameter. This vulnerability has been reported to exist in Open WebMail versions 2.50 20050212 and prior.
Open WebMail is prone to a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input. The problem presents itself when malicious HTML and script code is sent to the application through the 'logindomain' parameter. This vulnerability has been reported to exist in Open WebMail versions 2.50 20050212 and prior.