Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wc79-h887-58h9

Опубликовано: 14 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying arbitrary senderid parameters in delete confirmation requests.

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying arbitrary senderid parameters in delete confirmation requests.

EPSS

Процентиль: 14%
0.00229
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
nvd
3 дня назад

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying arbitrary senderid parameters in delete confirmation requests.

CVSS3: 4.3
debian
3 дня назад

Froxlor before 2.3.7 fails to properly scope sender alias lookups to t ...

EPSS

Процентиль: 14%
0.00229
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-200