SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-12970

XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2.

MEDIUM 6.1EPSS 1.82%

Does this matter?

Lower severity and a low EPSS score (1.82%). Track it; it rarely justifies an emergency change on its own.

Description

XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context via crafted use of (for example) a NOEMBED, NOFRAMES, NOSCRIPT, or TEXTAREA element.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.82% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
squirrelmail/squirrelmail
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.