S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-43574 Scanner

CVE-2021-43574 scanner - Cross-Site Scripting (XSS) vulnerability in Atmail

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-43574
6.1
CVSS

WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Atmail is a popular email hosting solution that allows businesses to create and manage their email accounts. This web-based application provides its users with an intuitive and easy-to-use interface that is packed with features including email administration, spam filtering, virus protection, and calendar management. The Atmail 6.5.0 version, which was released in 2012, however, is no longer supported by the vendor, leaving it exposed to security vulnerabilities.

CVE-2021-43574 is one of such security vulnerabilities detected in this product. This particular vulnerability can be exploited through the WebAdmin Control Panel and is available via the format parameter to the default URI. This means that attackers can inject malicious code into emails to execute malicious attacks, making the system vulnerable to cross-site scripting (XSS).

When CVE-2021-43574 is exploited, it can lead to significant damage to the system's security and integrity. Attackers can potentially trick users into clicking on malicious links or executing scripts that steal sensitive information such as login credentials, personal data, or company secrets. The end result could cause severe damage to the reputation of the business and even lead to financial losses.

At s4e.io, our pro features provide individuals and businesses with the ability to quickly and easily learn about vulnerabilities in their digital assets. With this platform, users can search for vulnerabilities by specific product name, type of vulnerability, and severity level. By leveraging our tools and resources, you can stay ahead of the curve and prevent security risks before they become serious threats.

 

REFERENCES

Solution Advice

The CVE record for the vulnerability was published with the label "Unsupported When Assigned". This indicates that the vulnerability of the product has not been and will not be resolved by the manufacturer. We recommend that you do not use products that are in End-of-Support status, and that you examine different equivalent products instead of this software. In this process, you can take the following precautions to reduce the attack surface in order to reduce the possibility of exploiting the vulnerability;

  • Limit physical and network access to the device.
  • Implement proper network segmentation and access control lists.
  • Monitor network traffic for signs of malicious activity.
     

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-43574 scanner - Cross-Site Scripting (XSS) vulnerability in Atmail | S4E