Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4fw6-qxc4-gqgq

Опубликовано: 03 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.7

Описание

SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.

SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.

EPSS

Процентиль: 38%
0.0045
Низкий

7.7 High

CVSS4

Дефекты

CWE-287

Связанные уязвимости

nvd
12 дней назад

SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.

EPSS

Процентиль: 38%
0.0045
Низкий

7.7 High

CVSS4

Дефекты

CWE-287