mirror of
https://github.com/0xMarcio/cve.git
synced 2025-06-02 03:30:48 +00:00
18 lines
838 B
Markdown
18 lines
838 B
Markdown
![]() |
### [CVE-2022-31470](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31470)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a logged-in user), can access and retrieve mailbox content.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- http://packetstormsecurity.com/files/174551/Axigen-10.5.0-4370c946-Cross-Site-Scripting.html
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/amirzargham/CVE-2023-08-21-exploit
|
||
|
|