KMMail E-Mail HTML Injection Vulnerability...

- AV AC AU C I A
发布: 2002-10-21
修订: 2025-04-13

kmMail does not sufficiently sanitize HTML and script code from the body of e-mail messages. As a result, an attacker may send a malicious message to a user of kmMail that includes arbitrary HTML and script code. This may allow an attacker to steal cookie-based authentication credentials from users of the webmail system. Other attacks are also possible.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息