Description
|
|
Two vulnerabilities have been identified in Symantec Brightmail Gateway, which could be exploited by malicious users to inject malicious scripts or gain elevated privileges.
The first issue is caused by unspecified errors in certain administrative scripts within the Brightmail Control Center, which could allow malicious users to disclose sensitive information, or gain access to other users' sessions, or to other systems on the internal network.
The second issue is caused by input validation errors in the Brightmail Control Center when processing external client input from users authorized to access to the console, which could be exploited to cause arbitrary scripting code to be executed by a user's browser in the security context of an affected site.
|