CVE-2014-3878 | Ipswitch IMail 12.3/12.4 Calendar cross site scripting (EDB-33633 / Nessus ID 76490)
A vulnerability was found in Ipswitch IMail 12.3/12.4. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Calendar Handler. The manipulation with the input G<IFRAME SRC="javascript:alert('XSS');"></IFRAME>S! leads to cross site scripting.
This vulnerability is handled as CVE-2014-3878. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.