Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.Referenceshttps://www.contextis.com/en/resources/advisories/cve-2018-15512