CVE-2023-49101

WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mishandling of viewing the usage of SSL certificates.
References
Link Resource
https://www.axigen.com/kb/show/400 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:axigen:axigen_mobile_webmail:*:*:*:*:*:*:*:*
cpe:2.3:a:axigen:axigen_mobile_webmail:*:*:*:*:*:*:*:*
cpe:2.3:a:axigen:axigen_mobile_webmail:*:*:*:*:*:*:*:*

History

15 Feb 2024, 16:00

Type Values Removed Values Added
CPE cpe:2.3:a:axigen:axigen_mobile_webmail:*:*:*:*:*:*:*:*
First Time Axigen
Axigen axigen Mobile Webmail
CWE CWE-79
Summary
  • (es) WebAdmin en Axigen 10.3.x anterior a 10.3.3.61, 10.4.x anterior a 10.4.24 y 10.5.x anterior a 10.5.10 permite ataques XSS contra administradores debido al mal manejo de la visualización del uso de certificados SSL.
References () https://www.axigen.com/kb/show/400 - () https://www.axigen.com/kb/show/400 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

08 Feb 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-08 22:15

Updated : 2024-02-15 16:00


NVD link : CVE-2023-49101

Mitre link : CVE-2023-49101

CVE.ORG link : CVE-2023-49101


JSON object : View

Products Affected

axigen

  • axigen_mobile_webmail
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')