Executive brief
Soliton Systems MailZen Management Portal is an administrative interface used to manage email and user accounts. A stored cross-site scripting vulnerability in user configuration fields allows authenticated administrators to inject malicious JavaScript code that executes in other administrators' browsers, potentially leading to unauthorized actions, account compromise, or lateral movement within the system.
Technical details
This is a stored cross-site scripting (XSS) vulnerability with HTML injection impact in the Soliton Systems MailZen Management Portal administrative interface. The vulnerability exists due to insufficient input sanitization and output encoding in multiple fields including Role Name, First Name, Last Name, and Username within user role and account creation modules. An authenticated attacker with administrative privileges can inject arbitrary JavaScript/HTML payloads into these fields; when other administrators view the affected data, the malicious code executes in their browser context. The vulnerability affects versions v2.62 and v2.63, and a fix is available in v2.64 GA released in June 2026.
Affected products
- Soliton Systems MailZen Management Portal v2.62, v2.63
Timeline
- 2026-04: disclosed: Vulnerability discovered and validated
- 2026-06-17: patched: MailZen Management Portal v2.64 GA released
- 2026-06-19: advisory: Public security advisory published
- 2026-08-05: other: CVE-2026-51144 published