Cross-site scripting (XSS) vulnerability in WebMail Pro in IceWarp Software Merak Mail Server 9.3.2 allows remote attackers to inject arbitrary web script or HTML via an IMG element in an HTML e-mail message.
Threat-Mapped Scoring
Score: 0.0
Priority: Unclassified
EPSS
Score: 0.00329 Percentile:
0.55261
CVSS Scoring
CVSS v2 Score: 4.3
Severity:
Mapped CWE(s)
CWE-79
: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')