HomeDefault status
unaffected
5.4.2.002 (semver) before 5.4.2.002
affected
Description
the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL parameter
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation
Product status
5.4.2.002 (semver) before 5.4.2.002
References
bugcrowd.com/...e-error-parameter-in-barracuda-mail-archiver
bugcrowd.com/...e-error-parameter-in-barracuda-mail-archiver