CVE-2017-14597: Afterlogic Aurora
Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.
AdminPanel in AfterLogic WebMail 7.7 and Aurora 7.7.5 has XSS via the txtDomainName field to adminpanel/modules/pro/inc/ajax.php during addition of a domain.
Affected products
- Afterlogic Aurora: version 7.7.5 only
- Afterlogic Webmail: version 7.7 only
Published 2017-09-19. Last modified 2026-06-17.