mailcow < 2026-03b reflects raw REQUEST_URI into JavaScript and href links on the login page, allowing attackers to inject parameters that break JS logic and enable phishing.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view