CVE-2020-29133

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
27/11/2020
Last modified:
30/11/2020

Description

jsp/upload.jsp in Coremail XT 5.0 allows XSS via an uploaded personal signature, as demonstrated by a .jpg.html filename in the signImgFile parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:coremail_xt_project:coremail_xt:5.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools