Back

CVE-2002-0411

Cross-site scripting vulnerability in message.php for AeroMail before 1.45 allows remote attackers to execute Javascript as an AeroMail user via an email message with the script in the Subject line.

Published: Aug 12, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
aeromail aeromail 1.02
aeromail aeromail 1.10
aeromail aeromail 1.20
aeromail aeromail 1.26
aeromail aeromail 1.30
aeromail aeromail 1.40

GitHub Security Advisory GHSA-v7h4-hhwc-qr2c

Cross-site scripting vulnerability in message.php for AeroMail before 1.45 allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.76%

Top 15% most likely to be exploited

Threat Score 30.8 / 100

Data Sources

NVD EPSS GitHub