Back to Database
Status published
Medium
CVE-2010-4930
Cross-site scripting (XSS) vulnerability in index.php in @mail Webmail before...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in index.php in @mail Webmail before 6.2.0 allows remote attackers to inject arbitrary web script or HTML via the MailType parameter in a mail/auth/processlogin action.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-4930
Credits & Attribution
No credits recorded in the NVD database.
References
More from atmail
View All →CVE-2022-31200
Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms field....
Medium
6.1
CVE-2022-30776
atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter....
Medium
6.1
CVE-2021-43574
WebAdmin Control Panel in Atmail 6.5.0 (a version released in...
Medium
6.1
CVE-2017-9519
atmail before 7.8.0.2 has CSRF, allowing an attacker to create...
High
8.8
CVE-2017-9518
atmail before 7.8.0.2 has CSRF, allowing an attacker to change...
High
8.8
Affected Vendor
atmail
View all reports →Affected Software
webmail
Vulnerable Versions:
0, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8
Timeline
Official Publish:
October 9th, 2011
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.