← Back

Ability Mail Server

ability_mail_server

Vendor: Codecrafters • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Codecrafters
1Ability Mail Server
Jun 17, 2026
Mar 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as a...Show more
Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe.Show less
1Codecrafters
1Ability Mail Server
May 13, 2026
Dec 20, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version 4.2.4.