Altn
Altn Security Gateway FOR Email Servers: vulnerabilidades y CVE
Altn Security Gateway FOR Email Servers tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-37238 | Media (5.4) | 0.55% | — | 25 ago 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter. |
| CVE-2022-37245 | Media (5.4) | 0.61% | — | 25 ago 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint. |
| CVE-2022-37244 | Media (5.4) | 0.55% | — | 25 ago 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection. |
| CVE-2022-37243 | Media (5.4) | 0.61% | — | 25 ago 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint. |
| CVE-2022-37242 | Crítica (9.8) | 1.4% | — | 25 ago 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter. |
| CVE-2022-37241 | Media (5.4) | 0.61% | — | 25 ago 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoint. |
| CVE-2022-37240 | Crítica (9.8) | 1.4% | — | 25 ago 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter. |
| CVE-2022-37239 | Media (5.4) | 0.61% | — | 25 ago 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint. |