Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
mailcow-dockerized 2026-03b - Stored XSS in Queue Manager via unescaped
Vulnerability Description
mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Manager fetches mail queue entries from /api/v1/get/mailq/all, copies server-controlled Postfix queue fields into DataTables rows, and renders several of those fields as HTML without adequate output encoding. This issue affects mailcow-dockerized: 2026-03b.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
mailcow dockerized 跨站脚本漏洞
Vulnerability Description
mailcow dockerized是mailcow开源的一个应用程序。 mailcow dockerized 2026-03b版本存在跨站脚本漏洞,该漏洞源于管理员队列管理器存在存储型跨站脚本漏洞,可能导致服务器控制的Postfix队列字段被渲染为HTML且输出编码不足。
CVSS Information
N/A
Vulnerability Type
N/A