Impact
Soliton Systems MailZen Management Portal versions 2.62 and 2.63 contain a cross‑site scripting flaw that permits a remote attacker to inject arbitrary script code through the Role Name, First Name, Last Name, and Username fields. If not mitigated, the attacker can execute JavaScript in the victim’s browser, potentially enabling session hijacking, credential theft, or further attacks against internal resources. The vulnerability is a classic input validation weakness leading to XSS.
Affected Systems
The flaw affects the Soliton Systems MailZen Management Portal software, specifically releases 2.62 and 2.63. No additional vendor or product details are supplied, but the impact applies to any installation of these versions.
Risk and Exploitability
The CVSS score is not provided and the EPSS score is unavailable, so exact severity is unclear, but the vulnerability allows arbitrary code execution in a remote user’s browser. Because the vulnerability is accessible via publicly reachable fields, it can be exploited by unauthenticated users, as inferred from the description. The vulnerability is not listed in the CISA KEV catalog, indicating no known large‑scale exploitation at the time of reporting.
OpenCVE Enrichment