Stored cross-site scripting vulnerability exists in CGIs included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Stored cross-site scripting vulnerability exists in CGIs included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
| Vendor | Product | Versions |
|---|---|---|
| A.K.I Software | pmc.exe | 2.5.1.720 and earlier |
| A.K.I Software | pmam.exe | 2.5.1.1411 and earlier |
| A.K.I Software | pmum.exe (Standard edition) | 2.5.1.25451 and earlier |
| A.K.I Software | pmum.exe (Pro edition) | 2.5.1.25452 and earlier |
| A.K.I Software | pmum.exe (Standard + IMAP4 edition) | 2.5.1.25453 and earlier |
| A.K.I Software | pmum.exe (Pro + IMAP4 edition / Enterprise edition) | 2.5.1.25454 and earlier |
Not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS is the best forward-looking signal — see the EPSS row above.
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:
No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.