Record summary

CVE-2022-31470 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a logged-in user), can access and retrieve mailbox content.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBAxigen < 10.3.3.47_ 10.2.3.12 - Reflected XSSExploitDB exploitby AmirZarghamNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMAxigen WebMail - Cross-Site ScriptingCVSS 6.1

Axigen WebMail versions 10.5.0-4370c946 and older are vulnerable to reflected XSS via the m parameter in the /index.hsp endpoint.

Impact

Attackers can craft malicious URLs with JavaScript in the m parameter that executes when users access the link, potentially stealing session cookies, credentials, or performing unauthorized actions in the victim's Axigen WebMail account.

Remediation

Update Axigen WebMail to a version later than 10.5.0-4370c946 that properly sanitizes and encodes the m parameter.

WeaknessesCWE-79
AuthorsAmirZargham
Template tagscvecve2022axigenwebmailxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:axigen:webmail:*:*:*:*:*:*:*:*
Shodan: title:"Axigen"
FOFA: title="Axigen"

Source: ProjectDiscovery

References

4