CVE-2017-14597: Afterlogic Aurora

Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.

AdminPanel in AfterLogic WebMail 7.7 and Aurora 7.7.5 has XSS via the txtDomainName field to adminpanel/modules/pro/inc/ajax.php during addition of a domain.

Affected products

Published 2017-09-19. Last modified 2026-06-17.