← Vulnerability feed

Vulnerability record · CVE-2022-31470 · published 7 June 2022

CVE-2022-31470: Axigen Mobile WebMail reset-password page reflected XSS

Axigen · Axigen Mobile Webmail

Axigen Mobile WebMail contains a cross-site scripting flaw in the index_mobile_changepass.hsp reset-password section. An attacker can inject arbitrary JavaScript that executes in the context of a logged-in user's active session. Because the script runs in the victim's session, it can reach and retrieve mailbox content.

6.1 CVSS 3.1 Medium EPSS 53% · top 1.1% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a logged-in user), can access and retrieve mailbox content.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityThe flaw allows session-context access to mailbox content and has a high EPSS score, though it requires user interaction and no KEV listing exists.

What it is

Axigen Mobile WebMail contains a cross-site scripting flaw in the index_mobile_changepass.hsp reset-password section. An attacker can inject arbitrary JavaScript that executes in the context of a logged-in user's active session. Because the script runs in the victim's session, it can reach and retrieve mailbox content.

Impact

An attacker who gets a logged-in user to trigger the crafted request can run JavaScript in that user's session and read mailbox content. The CVSS scope change (S:C) reflects that the injected script can affect resources beyond the vulnerable component.

Attack surface

Reachable over the network via the Mobile WebMail reset-password page; no authentication is required to deliver the payload, but the victim must be logged in and must interact (UI:R) for the script to run in their session.

Exploitation

Not listed in CISA KEV and no ransomware use documented. EPSS is high (0.52721, 98.9th percentile), indicating elevated likelihood of exploitation activity, and public references include a Packet Storm advisory alongside vendor advisories.

What to do

  • Upgrade Axigen Mobile WebMail to 10.2.3.12 or later, or 10.3.3.47 or later for the 10.3.x line.
  • Apply the vendor advisory guidance for CVE-2022-31470.
  • Deploy a WAF rule to block script injection against index_mobile_changepass.hsp.
  • Enforce short session lifetimes and re-authentication for Mobile WebMail to limit the value of a hijacked session.
  • Restrict or disable Mobile WebMail where it is not required.

Detection

  • Inspect web logs for script payloads or unusual parameters sent to index_mobile_changepass.hsp.
  • Alert on outbound requests from Mobile WebMail sessions to unexpected external domains.
  • Monitor for anomalous mailbox access patterns from Mobile WebMail sessions, such as bulk message retrieval.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-31470 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2023-49101Axigen mobile webmail cross-site scripting vulnerabilityWebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mishandling…EPSS 0.19%5.4CVE-2023-40355Axigen mobile webmail cross-site scripting vulnerabilityCross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authen…EPSS 1.1%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed6.1CVE-2025-48700Zimbra Classic UI stored XSS via crafted email HTMLZimbra Collaboration Suite Classic UI fails to properly sanitize HTML content in email messages, allowing crafted tag structures and attribute values…KEVEPSS 1.7%analysed6.1CVE-2025-66376Zimbra Collaboration Classic UI stored XSS via CSS @import in emailZimbra Collaboration Suite 10 before 10.0.18 and 10.1 before 10.1.13 allows stored cross-site scripting in the Classic UI through CSS @import directi…KEVEPSS 20%analysed6.1CVE-2025-68461Roundcube Webmail XSS via SVG animate tagRoundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is vulnerable to cross-site scripting through the animate tag in an SVG document. Because the f…KEVEPSS 27%analysed10.0CVE-2026-22769Dell RecoverPoint for Virtual Machines hardcoded credential flawDell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798). An unauthenticated remot…KEVEPSS 13%analysed7.1CVE-2025-14611Gladinet CentreStack and Triofox hardcoded AES key enables file inclusionCentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints.…KEVEPSS 53%analysed

Source: NIST National Vulnerability Database (record CVE-2022-31470), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.