A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface.

Published at
2019-04-22
1000 days ago
Modified
2019-04-24
998 days ago
2019
Year
The year of the turtle

http://www.securityfocus.com/bid/108046

BID:108046

https://www.openwall.com/lists/oss-security/2019/04/20/1

MLIST:[oss-security] 20190420 [CVE-2019-0218] Apache Pony Mail (incubating) Reflected XSS

https://lists.apache.org/thread.html/18a7ff26bc31a77e32e5e02e65dc86b1c41b610c753f8927d2cf955a@%3Cdev.ponymail.apache.org%3E

MLIST:[ponymail-users] 20190420 [CVE-2019-0218] Apache Pony Mail (incubating) Reflected XSS

Vulnerability RAW

{
	"Title": {
		"_text": "CVE-2019-0218"
	},
	"Notes": {
		"Note": [
			{
				"_text": "A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface."
			},
			{
				"_text": "2019-04-22"
			},
			{
				"_text": "2019-04-24"
			}
		]
	},
	"CVE": {
		"_text": "CVE-2019-0218"
	},
	"References": {
		"Reference": [
			{
				"URL": {
					"_text": "http://www.securityfocus.com/bid/108046"
				},
				"Description": {
					"_text": "BID:108046"
				}
			},
			{
				"URL": {
					"_text": "https://www.openwall.com/lists/oss-security/2019/04/20/1"
				},
				"Description": {
					"_text": "MLIST:[oss-security] 20190420 [CVE-2019-0218] Apache Pony Mail (incubating) Reflected XSS"
				}
			},
			{
				"URL": {
					"_text": "https://lists.apache.org/thread.html/18a7ff26bc31a77e32e5e02e65dc86b1c41b610c753f8927d2cf955a@%3Cdev.ponymail.apache.org%3E"
				},
				"Description": {
					"_text": "MLIST:[ponymail-users] 20190420 [CVE-2019-0218] Apache Pony Mail (incubating) Reflected XSS"
				}
			}
		]
	}
}