Qualitia Active! Mail 6 Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Active! Mail 6, specifically in versions 6.30.01004145 prior to 6.60.06008562. This vulnerability allows an attacker to execute arbitrary scripts in the context of the logged-in user's web browser by accessing a specially crafted URL.
Impact
Exploitation of this vulnerability allows for the execution of arbitrary scripts in the user's web browser, potentially leading to unauthorized actions being performed on behalf of the user.
Remediation
Users are advised to update Active! Mail 6 to the latest version, 6.61.01008654. Alternatively, the latest version can be used with an updated compatible web browser.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
