安全研究

CVE-2025-44148 MailEnable Webmail 反射 XSS:failure.aspx 未净化的 state 参数

#漏洞分析#代码审计#Web安全
CVE-2025-44148 MailEnable Webmail 反射 XSS:failure.aspx 未净化的 state 参数

MailEnable Webmail 的 failure.aspx 在显示错误页时把 state 参数原封不动写入 HTML——攻击者构造 state=<script>...</script> 的 URL,受害者点击后 MailEnable 不做 sanitize 直接回显,触发反射型 XSS,盗取 session、cookies、发起钓鱼。

Unlock to view this content.