CVE-2018-14951
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.
MEDIUM · CVSS 6.1
EPSS 0.00533
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0