CVE-2012-2593 EXPLOIT
6.1
MEDIUM · CVSS 3.1 · EPSS 6.2% (pctl 93)
Patch early
A public exploit exists.
Description
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date field of an email.
Scoring
| CVSS | 6.1 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 6.23% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-02-06 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| atmail | atmail |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | AtMail Email Server Appliance 6.4 - Persistent Cross-Site Scripting / Cross-Site Request Forgery / Remote Code Execution | 2012-07-21 |
References
→ the Explorer · watch your stack · NVD