CVE-2019-9538: Telos Automated Message Handling System
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the LDAP cbURL parameter of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.
Affected products
- Telos Automated Message Handling System: before 4.1.5.5 (fixed in 4.1.5.5)
Published 2020-01-03. Last modified 2026-06-17.