Описание
Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_to and subject parameters.
Ссылки
- Exploit
- US Government Resource
- Patch
- Exploit
- US Government Resource
- Patch
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:squirrelmail:squirrelmail:1.2.2:*:*:*:*:*:*:*
EPSS
Процентиль: 88%
0.03437
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
debian
больше 23 лет назад
Cross-site request forgery (CSRF) vulnerability in compose.php in Squi ...
github
больше 4 лет назад
Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_to and subject parameters.
EPSS
Процентиль: 88%
0.03437
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other