Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Surgemail | Netwin | 2.2g3 (including) | 2.2g3 (including) |