atmail 7 Stored XSS Vulnerability

by Zach Julian, on Jun 23, 2017 1:24:27 PM

Patch Date

May 25, 2017

Reported Date

February 23, 2017

Vendor

ATMAIL

Systems Affected

atmail 7

Summary

A stored XSS vulnerability was identified in the webmail component of atmail 7. By sending a specially crafted email to a victim, an attacker can include an XSS payload to steal user contacts, send arbitrary emails, expose inbox contents, and more.

Vendor Status

This vulnerability was remediated in atmail 7.8.0.2, released on May 25, 2017. CVE-2017-11617 was issued to the vulnerability. 

Disclosure timeline:

2017-02-24 – Vulnerability reported

2017-02-27 – Report acknowledged

2017-05-25 – Patch released

Exploit Availability

Full details regarding this vulnerability can be found in the accompanying blog post.

Researcher

Zach Julian of Bishop Fox

For Reference

Minor Update 7.8.0.2/ActiveSync 2.3.6

Vulnerabilities:Cross-site Scripting

Comments

Vulnerability Disclosure Policy

Bishop Fox takes security issues very seriously. We believe in coordinated disclosure, and we work closely with vendors and clients to patch vulnerabilities promptly. More on our Disclosure Policy →

Subscribe to Updates