6.1
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Description
the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL parameter
Basic Information
ID
CVE-2025-8319
Source
Bugcrowd
Published
Jul 29, 2025 at 23:31
Modified
Jul 30, 2025 at 15:06
Affected Product
Vendor
Barracuda
Product
Barracuda Message Archiver
Version
5.4.2.002
Affected Versions
Barracuda Barracuda Message Archiver 5.4.2.002