PT-2022-20748 · Axigen · Axigen Mobile Webmail

CVE-2022-31470

·

Published

2022-06-07

·

Updated

2023-09-09

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Axigen Mobile WebMail versions prior to 10.2.3.12 Axigen Mobile WebMail versions 10.3.x prior to 10.3.3.47
Description The issue allows attackers to run arbitrary Javascript code, using an active end-user session for a logged-in user, to access and retrieve mailbox content. This is due to an XSS vulnerability in the index mobile changepass.hsp reset-password section.
Recommendations For versions prior to 10.2.3.12, update to version 10.2.3.12 or later. For versions 10.3.x prior to 10.3.3.47, update to version 10.3.3.47 or later. As a temporary workaround, consider restricting access to the index mobile changepass.hsp reset-password section until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31470

Affected Products

Axigen Mobile Webmail