Qualitia Active! Mail 6 Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Active! Mail 6, specifically in versions 6.30.01004145 prior to 6.60.06008562. This vulnerability allows an attacker to execute arbitrary scripts in the context of the logged-in user's web browser by accessing a specially crafted URL.

Impact

Exploitation of this vulnerability allows for the execution of arbitrary scripts in the user's web browser, potentially leading to unauthorized actions being performed on behalf of the user.

Remediation

Users are advised to update Active! Mail 6 to the latest version, 6.61.01008654. Alternatively, the latest version can be used with an updated compatible web browser.

Added: Jul 2, 2025, 5:19 AM
Updated: Jul 2, 2025, 5:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.0
exploitability
6.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.