CVE-2022-39258
published 2022-09-27CVE-2022-39258: mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Authorize links…
PriorityP350high8.2CVSS 3.1
AVNACLPRNUIRSCCHILAN
EXPLOIT
EPSS
1.52%
73.5th percentile
mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Authorize links. This could redirect a victim to an attacker controller place to steal Swagger authorization credentials or create a phishing page to steal other information. The issue has been fixed with the 2022-09 mailcow Mootember Update. As a workaround, one may delete the Swapper API Documentation from their e-mail server.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mailcow | mailcow | < 2022-09 | 2022-09 |
| mailcow | mailcow-dockerized | < 2022-09 | 2022-09 |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
No detection rules found.
Nuclei
Mailcow Dockerized Swagger UI - Cross-Site Scripting
nuclei·CVSS 8.2
CVE-2022-39258 [HIGH] Mailcow Dockerized Swagger UI - Cross-Site Scripting
Mailcow Dockerized Swagger UI - Cross-Site Scripting
Mailcow-dockerized before 2022-09a uses a vulnerable version of Swagger UI (before 4.11.1) that is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. When a user accesses the Swagger documentation with a crafted configUrl or url parameter containing JavaScript payloads, arbitrary code execution can occur in the user's browser. This allows attackers to steal cookies, session data, or execute actions on behalf of the victim by enticing them to open a malicious Swagger UI link.
Template:
id: CVE-2022-39258
info:
name: Mailcow Dockerized Swagger UI - Cross-Site Scripting
author: ritikchaddha
severity: medium
description: |
Mailcow-dockerized before 2022-09a uses a vulnerable version of Swagger UI (before 4.11.1) that is af
No writeups or analysis indexed.
2022-09-27
Published