La pagina di visualizzazione messaggio di posta in SquirrelMail attraverso 1.4.22 ha XSS tramite animazioni SVG (animate all’attributo). |
https://lists.fedoraproject.org/archives/list/[email protected]/message/T5FP5O562A4FM5TCFNEW73SS6PZONSAC/ https://lists.fedoraproject.org/archives/list/[email protected]/message/CVXTYMZ35IC5KPNMAE6BWAQWURMX7KZO/ http://www.openwall.com/lists/oss-security/2018/07/26/2 https://bugs.debian.org/905023 https://sourceforge.net/p/squirrelmail/bugs/2831/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14955 |
Vulnerabilità: CVE-2018-14955
