Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 7 min 99 bronnen 3 kritiek 1 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2026-32851

MEDIUM · 6.1 CVSS Gepubliceerd: CWE-79

Beschrijving

MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to execute arbitrary JavaScript in a victim's browser by crafting a malicious URL. Attackers can inject malicious code through the StartDate parameter in the FreeBusy.aspx form, which is not properly sanitized before being embedded into dynamically generated JavaScript.

Vendors

Mailenable

Affected products

Mailenable

References