CVE-2014-3878 | Ipswitch IMail up to 12.4.1.14 Contact Details cross site scripting (EDB-33633 / Nessus ID 76490)
A vulnerability was found in Ipswitch IMail up to 12.4.1.14. It has been classified as problematic. Affected is an unknown function of the component Contact Details Handler. The manipulation with the input <iframe src="http://www.scip.ch"; height=500 width=500 frameborder=1 align=center></iframe> leads to cross site scripting.
This vulnerability is traded as CVE-2014-3878. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.