cvedb.io
CVE-2023-28705
MEDIUM · CVSS 5.4
EPSS exploitation probability: 0%
Published 2023-06-02T11:15:10.720 · Last modified 2026-06-17T05:48:35.950

Summary

Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. A remote attacker can exploit this vulnerability using phishing emails that contain malicious web pages injected with JavaScript. When users access the system and open the email, it triggers an XSS (Reflected Cross-site scripting) attack.

Affected products

openfind — mail2000

Does this affect you?

Add your gear to cvedb and we'll alert you only when openfind ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.