Security Advisory
CVE-2015-9279
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.