Analysis on rafaelpfister.ch

Vendor description

Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.

Reference data

Vendor
Kiteworks
Affected products
  • totemomail
CVSS 3.1
6.1 (MEDIUM)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness type
CWE-79: Cross-Site Scripting
Published
May 18, 2024

Official sources

← All vulnerabilities