Cross-site scripting (XSS) vulnerability in webmail in Open-Xchange 0.8.1-6 and earlier, with Inline HTML enabled, allows remote attackers to inject arbitrary web script or HTML via e-mail attachments, which are rendered inline.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Open-xchange | Open-xchange | * | 0.8.1.6 (including) |