Bulwark Webmail versions prior to 1.4.11 contain a cross-site scripting (XSS) vulnerability in the reverse proxy component. The application incorrectly deployed the Content-Security-Policy-Report-Only header instead of the enforcing Content-Security-Policy header, allowing XSS attacks to be logged rather than blocked. An authenticated attacker could inject malicious script content through crafted email HTML to execute arbitrary JavaScript within the application context, potentially compromising session tokens or performing unauthorized actions. The vulnerability carries a CVSS score of 5.4 (Medium) with a network-based attack vector requiring low complexity and user interaction. Exploitation requires prior authentication (PR:L) and results in limited confidentiality and integrity impact. The EPSS score of 0.0003 indicates extremely low probability of exploitation in the wild relative to other known vulnerabilities. There is no evidence of active exploitation in the wild, no known public exploit code, and no designation on the KEV catalog or CISA Hot List. The vulnerability appears to have minimal community attention and low real-world exploitation risk. Organizations running Bulwark Webmail should prioritize updating to version 1.4.11 or later as part of routine patching cycles rather than emergency response procedures.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.11CPE matchmatch criteria | cpe:2.3:a:bulwarkmail:webmail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.