Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter. Attackers can exploit this by deploying a multi-stage attack. In the first stage, a malicious JavaScript payload is injected into the timeFormat preference by exploiting a separate vulnerability or using compromised credentials. In the second stage, when the victim logs into the WebMail interface, the unsanitized timeFormat value is loaded from storage and inserted into the DOM, causing the injected script to execute.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Axigen Mail Server 安全漏洞
Vulnerability Description
Axigen Mail Server是Axigen公司的一款邮件服务器软件。 Axigen Mail Server 10.5.57之前版本存在安全漏洞,该漏洞源于处理timeFormat账户偏好参数时存在存储型跨站脚本,攻击者可通过多阶段攻击注入并执行恶意JavaScript有效载荷。
CVSS Information
N/A
Vulnerability Type
N/A