Impact
Soliton Systems MailZen Management Portal versions 2.62 and 2.63 contain a cross‑site scripting flaw that permits a remote attacker to inject arbitrary script code through the Role Name, First Name, Last Name, and Username fields. If not mitigated, the attacker can execute JavaScript in the victim’s browser, potentially enabling session hijacking, credential theft, or further attacks against internal resources. The vulnerability is a classic input validation weakness leading to XSS.
Affected Systems
The flaw affects the Soliton Systems MailZen Management Portal software, specifically releases 2.62 and 2.63. No additional vendor or product details are supplied, but the impact applies to any installation of these versions.
Risk and Exploitability
The CVSS score has been updated to 6.1 and the EPSS score remains < 1%. With a CVSS score of 6.1, the vulnerability is classified as medium severity. It allows arbitrary code execution in a remote user’s browser. Because the vulnerability is accessible via publicly reachable fields, it can be exploited by unauthenticated users, as inferred from the description. The vulnerability is not listed in the CISA KEV catalog, indicating no known large‑scale exploitation at the time of reporting.
OpenCVE Enrichment