What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in cstoltenkamp Free MailClient FMC mailclient allows Stored XSS.This issue affects Free MailClient FMC: from n/a through <= 1.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in cstoltenkamp Free MailClient FMC mailclient allows Stored XSS.This issue affects Free MailClient FMC: from n/a through <= 1.0.
Explanation of Vulnerability in Simple Terms
Free MailClient FMC versions 1.0 and earlier are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in user, performs unwanted actions within the mail client without the user's knowledge. The vulnerability affects confidentiality, integrity, and availability of the application.
What an attacker can do
Perform unwanted actions in the mail client on behalf of a logged-in user without their consent.
Potential impact on your site
Users' mail accounts and data can be compromised through forged requests if they visit malicious sites while logged in.
Conditions required to exploit
User must be logged into Free MailClient FMC and visit an attacker-controlled webpage.
Key dates
External resources
Related vulnerabilities