CVE-2017-11617
MEDIUMatmail <7.8.0.2 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML within the body of an email via an IMG element with both single quotes and double quotes.
Scores
CVSS v3
6.1
EPSS
0.0026
EPSS Percentile
49.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
atmail/atmail
< 7.8.0.1
n/a/n/a
Published
Jul 25, 2017
Tracked Since
Feb 18, 2026