Symantec Encryption Management Server Email Attachments Script Insertion Vulnerability
Last Update Date:
24 Jul 2013 12:43
Release Date:
24 Jul 2013
3917
Views
RISK: Medium Risk
TYPE: Servers - Other Servers
A vulnerability has been identified in Symantec Encryption Management Server, which can be exploited by malicious users to conduct script insertion attacks.
Certain unspecified input related to encrypted email attachments is not properly sanitised within the Web Email Protection component before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site if malicious data is viewed.
Impact
- Cross-Site Scripting
System / Technologies affected
- Versions prior to 3.3.0 MP2.
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 3.3.0 MP2.
Vulnerability Identifier
Source
Related Link
Share with