CVE-2020-29133
27.11.2020, 01:15
jsp/upload.jsp in Coremail XT 5.0 allows XSS via an uploaded personal signature, as demonstrated by a .jpg.html filename in the signImgFile parameter.
Vendor | Product | Version |
---|---|---|
coremail_xt_project | coremail_xt | 5.0 |
𝑥
= Vulnerable software versions