VDB
Sign up
MEDIUM5.4

GHSA-jj4j-cwgq-fx7g

ViMbAdmin Cross-site Scripting Vulnerabilities

Details

Multiple cross-site scripting (XSS) vulnerabilities in ViMbAdmin 3.0.15 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) transport parameter to domain/add; the (3) name parameter to mailbox/add/did/<domain id>; the (4) goto parameter to alias/add/did/<domain id>; or the (5) captchatext parameter to auth/lost-password.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/opensolutions/vimbadmin
Introduced in: 0

No fixed version published yet for opensolutions/vimbadmin (composer). Pin to a known-safe version or switch to an alternative.

References