CVE-2017-5870

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
23/05/2017
Last modified:
20/04/2025

Description

Multiple cross-site scripting (XSS) vulnerabilities in ViMbAdmin 3.0.15 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) transport parameter to domain/add; the (3) name parameter to mailbox/add/did/; the (4) goto parameter to alias/add/did/; or the (5) captchatext parameter to auth/lost-password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vimbadmin:vimbadmin:3.0.15:*:*:*:*:*:*:*