Cross-site scripting (XSS) vulnerability in Open WebMail 2.x allows remote attackers to inject arbitrary HTML or web script via the domain name parameter (logindomain) in the login page.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Open_webmail | Open_webmail | 2.00 (including) | 2.00 (including) |
| Open_webmail | Open_webmail | 2.01 (including) | 2.01 (including) |
| Open_webmail | Open_webmail | 2.10 (including) | 2.10 (including) |
| Open_webmail | Open_webmail | 2.20 (including) | 2.20 (including) |
| Open_webmail | Open_webmail | 2.21 (including) | 2.21 (including) |
| Open_webmail | Open_webmail | 2.30 (including) | 2.30 (including) |
| Open_webmail | Open_webmail | 2.32 (including) | 2.32 (including) |
| Open_webmail | Open_webmail | 2.40 (including) | 2.40 (including) |
| Open_webmail | Open_webmail | 2.41 (including) | 2.41 (including) |
| Open_webmail | Open_webmail | 2.50 (including) | 2.50 (including) |