CVE-2012-2593

MEDIUM

Atmail Webmail Server 6.4 - Cross-Site Scripting via Email Date Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2012-2593. PoCs published by muts, AndrewTrube.

AI-analyzed exploit summary This exploit leverages a CSRF vulnerability in Atmail Email Server 6.4 to send a malicious email containing JavaScript that triggers a remote plugin installation, leading to remote code execution. The payload includes a crafted plugin file uploaded via XMLHttpRequest.

Description

Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date field of an email.

Exploits (2)

exploitdb WORKING POC VERIFIED
by muts · pythonremotelinux
https://www.exploit-db.com/exploits/20009

This exploit leverages a CSRF vulnerability in Atmail Email Server 6.4 to send a malicious email containing JavaScript that triggers a remote plugin installation, leading to remote code execution. The payload includes a crafted plugin file uploaded via XMLHttpRequest.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Atmail Email Server 6.4
Auth required
Prerequisites: Valid credentials for the Atmail server · Admin interface must be open in the victim's browser
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by AndrewTrube · poc
https://github.com/AndrewTrube/CVE-2012-2593

This repository contains a proof-of-concept exploit for CVE-2012-2593, which chains XSS and CSRF vulnerabilities in Atmail webmail to achieve remote code execution via a malicious plugin installation. The exploit includes a reverse shell payload and detailed instructions for execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Atmail webmail server version 6.4
Auth required
Prerequisites: Admin user must be logged into both webmail and admin interfaces · Plugin installation must be enabled on the server · Attacker must have a netcat listener set up
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://www.exploit-db.com/exploits/20009
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/bid/54630

Scores

CVSS v3 6.1
EPSS 0.0623
EPSS Percentile 92.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
atmail/atmail 6.4.0
Published Feb 06, 2020
Tracked Since Feb 18, 2026