← back
CVE-2023-22902mediumCWE-79

Openfind Mail2000 - XSS

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.4epss 0.4%
exploitation probability
0.4%top 63% of all CVEs
observed exploitation
nono source reports it
Openfind Mail2000 file uploading function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can exploit this vulnerability to inject JavaScript, conducting an XSS attack.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products
Openfind · Mail2000