VulnerabilityModified
CVE-2023-28705
A remote attacker can exploit this vulnerability using phishing emails that contain malicious web pages injected with JavaScript.
MEDIUM 6.1EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. A remote attacker can exploit this vulnerability using phishing emails that contain malicious web pages injected with JavaScript. When users access the system and open the email, it triggers an XSS (Reflected Cross-site scripting) attack.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- openfind/mail2000
- Source
- twcert@cert.org.tw
References
- https://www.twcert.org.tw/tw/cp-132-7158-751a6-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-7158-751a6-1.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.