Loading HuntDB...

GHSA-7j4f-2m7v-2cjv

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/mail/main/select_send.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

Related CVEs

Key Information

GHSA ID
GHSA-7j4f-2m7v-2cjv
Published
March 18, 2024 3:30 PM
Last Modified
April 17, 2025 9:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.