All CVEs — page 45 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows a remote, unauthenticated attacker to inject JScript code into hMailServer, potentially leading to command execution as the service account.
The flaw allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS) attacks by injecting malicious scripts through the email-locked download subscription form, which could lead to data exfiltration, information disclosure, and potential administrative control.