CVE-2012-3536: Apache Hupa
Medium severity, CVSS 6.1. EPSS: 1.9% chance of exploitation in the next 30 days.
Two XSS vulnerabilities were fixed in message list and view in the Hupa Webmail application from the Apache James project. An attacker could send a carefully crafted email to a user of Hupa which would trigger a XSS when the email was opened or when a list of messages were viewed. This issue was addressed in Hupa 0.0.3.
Affected products
- Apache Hupa: before 0.0.3 (fixed in 0.0.3)
Published 2018-02-27. Last modified 2026-06-16.