Synopsis
The remote host is running OpenWebmail, an open-source perl script that gives remote users a web-based interface to email.
Description
The remote host is running OpenWebmail, an open-source perl script that gives remote users a web-based interface to email. This version of OpenWebmail is vulnerable to a cross-site scripting (XSS) attack. An attacker exploiting this flaw would be need to be able to convince a user to click on a malicious URL. Upon successful exploitation, the attacker would be able to steal credentials or execute code within the browser.
Solution
Upgrade or patch according to vendor recommendations.
Plugin Details
Risk Information
Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Temporal Vector: CVSS:3.0/E:H/RL:O/RC:X
Vulnerability Information
CPE: cpe:/a:open_webmail:open_webmail