SqWebMail.Email.Header.HTML.Injection

description-logoDescription

It indicates a possible exploit of Cross-Site Scripting vulnerability in SqWebMail that may allow attacker to gain access to an unsuspecting users cookie via a crafted email header.

affected-products-logoAffected Products

Inter7 SqWebMail 4.0.4.

Impact logoImpact

Information based on cookies disclosue.

recomended-action-logoRecommended Actions

Upgrade to version 4.0.5 or later.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)