Vulnerability record · CVE-2022-31470 · published 7 June 2022
CVE-2022-31470: Axigen Mobile WebMail reset-password page reflected XSS
Axigen · Axigen Mobile Webmail
Axigen Mobile WebMail contains a cross-site scripting flaw in the index_mobile_changepass.hsp reset-password section. An attacker can inject arbitrary JavaScript that executes in the context of a logged-in user's active session. Because the script runs in the victim's session, it can reach and retrieve mailbox content.
Description
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a logged-in user), can access and retrieve mailbox content.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe flaw allows session-context access to mailbox content and has a high EPSS score, though it requires user interaction and no KEV listing exists.
What it is
Axigen Mobile WebMail contains a cross-site scripting flaw in the index_mobile_changepass.hsp reset-password section. An attacker can inject arbitrary JavaScript that executes in the context of a logged-in user's active session. Because the script runs in the victim's session, it can reach and retrieve mailbox content.
Impact
An attacker who gets a logged-in user to trigger the crafted request can run JavaScript in that user's session and read mailbox content. The CVSS scope change (S:C) reflects that the injected script can affect resources beyond the vulnerable component.
Attack surface
Reachable over the network via the Mobile WebMail reset-password page; no authentication is required to deliver the payload, but the victim must be logged in and must interact (UI:R) for the script to run in their session.
Exploitation
Not listed in CISA KEV and no ransomware use documented. EPSS is high (0.52721, 98.9th percentile), indicating elevated likelihood of exploitation activity, and public references include a Packet Storm advisory alongside vendor advisories.
What to do
- Upgrade Axigen Mobile WebMail to 10.2.3.12 or later, or 10.3.3.47 or later for the 10.3.x line.
- Apply the vendor advisory guidance for CVE-2022-31470.
- Deploy a WAF rule to block script injection against index_mobile_changepass.hsp.
- Enforce short session lifetimes and re-authentication for Mobile WebMail to limit the value of a hijacked session.
- Restrict or disable Mobile WebMail where it is not required.
Detection
- Inspect web logs for script payloads or unusual parameters sent to index_mobile_changepass.hsp.
- Alert on outbound requests from Mobile WebMail sessions to unexpected external domains.
- Monitor for anomalous mailbox access patterns from Mobile WebMail sessions, such as bulk message retrieval.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-31470 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-31470), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.