Описание
Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_to and subject parameters.
Ссылки
- Exploit
- US Government Resource
- Patch
- Exploit
- US Government Resource
- Patch
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:squirrelmail:squirrelmail:1.2.2:*:*:*:*:*:*:*
EPSS
Процентиль: 79%
0.01268
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
debian
почти 23 года назад
Cross-site request forgery (CSRF) vulnerability in compose.php in Squi ...
github
больше 3 лет назад
Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_to and subject parameters.
EPSS
Процентиль: 79%
0.01268
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other