{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-26T18:19:47.329","vulnerabilities":[{"cve":{"id":"CVE-2023-28705","sourceIdentifier":"twcert@cert.org.tw","published":"2023-06-02T11:15:10.720","lastModified":"2026-06-17T05:48:35.950","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. A remote attacker can exploit this vulnerability using phishing emails that contain malicious web pages injected with JavaScript. When users access the system and open the email, it triggers an XSS (Reflected Cross-site scripting) attack."},{"lang":"es","value":"Openfind Mail2000 tiene insuficientes caracteres especiales de filtrado de contenido de correo electrónico de su función de filtrado de contenido. Un atacante remoto puede explotar esta vulnerabilidad utilizando correos electrónicos de phising que contienen páginas web maliciosas inyectadas con JavaScript. Cuando los usuarios acceden al sistema y abren el correo electrónico, se desencadena un ataque XSS (Cross-site scripting) reflejado. "}],"affected":[{"source":"twcert@cert.org.tw","affectedData":[{"vendor":"Openfind","product":"Mail2000","versions":[{"version":"unspecified","lessThanOrEqual":"7","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"twcert@cert.org.tw","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-08T20:02:22.789681Z","id":"CVE-2023-28705","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"twcert@cert.org.tw","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openfind:mail2000:*:*:*:*:*:*:*:*","versionEndExcluding":"8.0","matchCriteriaId":"77C94079-D5D6-4A19-A1AA-C20AE4B9693E"}]}]}],"references":[{"url":"https://www.twcert.org.tw/tw/cp-132-7158-751a6-1.html","source":"twcert@cert.org.tw","tags":["Third Party Advisory"]},{"url":"https://www.twcert.org.tw/tw/cp-132-7158-751a6-1.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}