Headline
CVE-2022-31470: Mail Server Software | Axigen
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a logged-in user), can access and retrieve mailbox content.
WebMail Demo
Outlook & mobile sync included
LIVE DEMO
WebAdmin Demo
Axigen’s smart admin console
LIVE DEMO
Download Now
Full featured 60-day evaluation
START TRIAL
For Business
Manage your email, organize and share calendars, sync your mobile devices, all based on a secure and powerful mail server. The perfect answer for businesses of all sizes.
Business Messaging
For MSPs
Acquire new customers by offering a premium email server solution with a high degree of flexibility, allowing you to automate it within your existing infrastructure.
MSP Messaging
For Service Providers
Offer your customers secure, business-level email hosting with various value added services. An excellent solution for SPs, suitable for thousands to millions of users.
ISP Messaging
Next level Web clients
Manage your email and get stuff done easily with calendars, tasks or notes. Enjoy desktop usability in your browser via keyboard navigation and shortcuts, drag-and-drop, “live” email list view, frequent folders, email filters, out-of-office messages, individual blacklist / whitelist.
Live Webmail Demo
Simply in control
Manage day-to-day server operations via Axigen’s comprehensive WebAdmin — designed for optimized navigability, with quick links and contextual help. Automate your Linux mail server’s administration and provisioning using the Command Line Interface (CLI).
Live Webadmin Demo
Related news
Axigen versions 10.5.0–4370c946 and below suffer from a cross site scripting vulnerability.