Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j8r3-h5ph-8fcm

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.

The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.

EPSS

Процентиль: 70%
0.00649
Низкий

Связанные уязвимости

nvd
почти 20 лет назад

The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.

EPSS

Процентиль: 70%
0.00649
Низкий