Vulnerability Description
An issue was discovered in Openfind Mail2000 6.0 and 7.0 Webmail. XSS can occur via an '<object data="data:text/html' substring in an e-mail message (The vendor subsequently patched this).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openfind | Mail2000 | 6.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/keniver/1f6092242ee79a8456a86bb7624bc171ExploitThird Party Advisory
- https://www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-004.pd
- https://www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-005.pd
- https://gist.github.com/keniver/1f6092242ee79a8456a86bb7624bc171ExploitThird Party Advisory
- https://www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-004.pd
- https://www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-005.pd
FAQ
What is CVE-2019-9763?
CVE-2019-9763 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An issue was discovered in Openfind Mail2000 6.0 and 7.0 Webmail. XSS can occur via an '<object data="data:text/html' substring in an e-mail message (The vendor subsequently patched this).
How severe is CVE-2019-9763?
CVE-2019-9763 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-9763?
Check the references section above for vendor advisories and patch information. Affected products include: Openfind Mail2000.