GHSA-7crp-p2vc-69r7

    Dashboard / Vulnerabilities / GHSA-7crp-p2vc-69r7

    GHSA-7crp-p2vc-69r7

    Published: 14 May 2022Last Modified: 16 Feb 2024
    Aliases:

    Summary: Apache James Hupa Webmail application Cross-site Scripting Vulnerabilities

    Details: Two XSS vulnerabilities were fixed in message list and view in the Hupa Webmail application from the Apache James project. An attacker could send a carefully crafted email to a user of Hupa which would trigger a XSS when the email was opened or when a list of messages were viewed. This issue was addressed in Hupa 0.0.3.

    Affected packages

    Package

    Name: org.apache.james.hupa:hupa-parent

    Purl: pkg:maven/org.apache.james.hupa/hupa-parent

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.0.3

    Affected versions

    0.0.2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-7crp-p2vc-69r7 | CVE-DB