CVE-2020-29133
EUVD-2020-2151427.11.2020, 01:15
jsp/upload.jsp in Coremail XT 5.0 allows XSS via an uploaded personal signature, as demonstrated by a .jpg.html filename in the signImgFile parameter.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| coremail_xt_project | coremail_xt | 5.0 |
𝑥
= Vulnerable software versions