S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-30776 Scanner

CVE-2022-30776 scanner - Cross-Site Scripting (XSS) vulnerability in Atmail

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-30776
6.1
CVSS

atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Atmail is an email management software that is designed for businesses of all sizes. This software enables companies to manage their emails, calendar, and contacts within a single platform. It also provides users with features such as filtering, storage, and integration with other systems. Atmail is used by companies worldwide as an email management solution. It empowers businesses to optimize their email management systems, increase productivity and enhance communication amongst teams and customers.

However, the Atmail software has recently been reported to possess a vulnerability identified as CVE-2022-30776. This vulnerability can lead to an XSS (cross-site scripting) attack that could compromise a company's entire email management system. Attackers could utilize this vulnerability within the index.php/admin/index section of the software by entering illegal data into the error parameter.

This vulnerability can lead to severe consequences for businesses, including a loss of confidential data, network breaches, and even financial losses. By exploiting this vulnerability, attackers could gain unauthorized access to company emails and confidential data, leading to a data breach and subsequent exploitation of sensitive details. Hackers could also use this vulnerability to hijack an email account and launch spear-phishing attacks or extract sensitive information from the compromised account.

At s4e.io, our platform has advanced features that can quickly identify vulnerabilities within your company's digital assets. The platform's pro features will enable you to access information on the latest vulnerabilities, such as CVE-2022-30776 covered in this article. By using our platform, you can take an essential step towards protecting your business from cyber threats and maintaining the utmost security for your systems and data.

 

REFERENCES

Solution Advice

There are several precautions that businesses using Atmail can take to protect against this vulnerability. These include:

  • Updating the Atmail software to the latest version
  • Applying strict controls over inputs into functions, routines and algorithms
  • Implementing a web application firewall
  • Educating their employees on cybersecurity best practices, including password hygiene, email security measures, and recognizing phishing attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.