Openfind Mail2000 - XSS (Reflected Cross-site scripting)
Vulnerability Description
Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. A remote attacker can exploit this vulnerability using phishing emails that contain malicious web pages injected with JavaScript. When users access the system and open the email, it triggers an XSS (Reflected Cross-site scripting) attack.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-28705
Credits & Attribution
No credits recorded in the NVD database.
More from Openfind
View All →Affected Vendor
Openfind
View all reports →