Skip to main content

Symantec Encryption Management Server Email Attachments Script Insertion Vulnerability

Last Update Date: 24 Jul 2013 12:43 Release Date: 24 Jul 2013 3391 Views

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A vulnerability has been identified in Symantec Encryption Management Server, which can be exploited by malicious users to conduct script insertion attacks.

 

Certain unspecified input related to encrypted email attachments is not properly sanitised within the Web Email Protection component before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site if malicious data is viewed.


Impact

  • Cross-Site Scripting

System / Technologies affected

  • Versions prior to 3.3.0 MP2.

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.
  • Update to version 3.3.0 MP2.

Vulnerability Identifier


Source


Related Link