CVE-2014-3878 | Ipswitch IMail up to 12.4.1.14 Task cross site scripting (EDB-33633 / Nessus ID 76490)
A vulnerability categorized as problematic has been discovered in Ipswitch IMail up to 12.4.1.14. This affects an unknown part of the component Task Handler. The manipulation with the input <iframe src=http://www.mysite.com/remote/xss_h.html> leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2014-3878. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.