CVE-2015-5379
Summary
| CVE | CVE-2015-5379 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-23 18:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attackers to inject arbitrary web script or HTML via an email attachment. |
Risk And Classification
Primary CVSS: v3.0 5.4 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Problem Types: CWE-79 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 5.4 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| 2.0 | [email protected] | Primary | 3.5 | AV:N/AC:M/Au:S/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Axigen | Axigen Mail Server | 8.0 | All | All | All |
| Application | Axigen | Axigen Mail Server | 8.0.1 | All | All | All |
| Application | Axigen | Axigen Mail Server | 8.0.2 | All | All | All |
| Application | Axigen | Axigen Mail Server | 8.0.3 | All | All | All |
| Application | Axigen | Axigen Mail Server | 8.1.0 | All | All | All |
| Application | Axigen | Axigen Mail Server | 8.1.1 | All | All | All |
| Application | Axigen | Axigen Mail Server | 8.1.2 | All | All | All |
| Application | Axigen | Axigen Mail Server | 8.1.3 | All | All | All |
| Application | Axigen | Axigen Mail Server | 8.2.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 401 Authorization Required | af854a3a-2127-422b-91ae-364da2661108 | blogs.securiteam.com | Third Party Advisory, VDB Entry |
| AXIGEN Mail Server - Ajax WebMail 8.x security patch (CVE-2015-5379) | af854a3a-2127-422b-91ae-364da2661108 | www.axigen.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Axigen Cross Site Scripting ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.