Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j83h-383p-595c

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain privileges as that user, e.g. by extracting the ID from the user's answer or forward URLs.

Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain privileges as that user, e.g. by extracting the ID from the user's answer or forward URLs.

EPSS

Процентиль: 73%
0.0075
Низкий

Связанные уязвимости

nvd
больше 23 лет назад

Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain privileges as that user, e.g. by extracting the ID from the user's answer or forward URLs.

EPSS

Процентиль: 73%
0.0075
Низкий