Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p628-386j-64h8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails via the msg_confirm_move template. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread.

An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails via the msg_confirm_move template. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread.

EPSS

Процентиль: 37%
0.00157
Низкий

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails via the msg_confirm_move template. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread.

CVSS3: 6.5
nvd
больше 5 лет назад

An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails via the msg_confirm_move template. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread.

CVSS3: 6.5
debian
больше 5 лет назад

An Insecure Direct Object Reference vulnerability in Citadel WebCit th ...

EPSS

Процентиль: 37%
0.00157
Низкий

Дефекты

CWE-639