漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
mailcow: dockerized vulnerable to stored XSS in user login history real_rip
Vulnerability Description
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user dashboard's "Seen successful connections" (login history) renders the client IP from login logs without HTML escaping. Because the server trusts the X-Real-IP header as the source IP for logging, an attacker can inject HTML/JS into this field. This Self-XSS can be exploited by a Login CSRF to force the victim into the attacker's account, and then read emails in a previous browser tab. Version 2026-03b fixes the vulnerability.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
mailcow: dockerized 安全漏洞
Vulnerability Description
mailcow: dockerized是mailcow开源的一个docker化的mailcow应用软件。 mailcow: dockerized 2026-03b之前版本存在安全漏洞,该漏洞源于用户仪表板登录历史中未对客户端IP进行HTML转义,且服务器信任X-Real-IP标头,可能导致攻击者注入HTML/JS,结合登录CSRF读取受害者邮件。
CVSS Information
N/A
Vulnerability Type
N/A