Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-3815

Опубликовано: 08 янв. 2018
Источник: nvd
CVSS3: 5.7
CVSS2: 3.5
EPSS Низкий

Описание

The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in CommuniGate Pro (CGP) 6.2 suffers from a Missing XIMSS Protocol Validation attack that leads to an email spoofing attack, allowing a malicious authenticated attacker to send a message from any source email address. The attack uses an HTTP POST request to a /Session URI, and interchanges the XML From and To elements.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:stalker:communigate_pro:6.2:*:*:*:*:*:*:*

EPSS

Процентиль: 47%
0.00238
Низкий

5.7 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.7
github
больше 3 лет назад

The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in CommuniGate Pro (CGP) 6.2 suffers from a Missing XIMSS Protocol Validation attack that leads to an email spoofing attack, allowing a malicious authenticated attacker to send a message from any source email address. The attack uses an HTTP POST request to a /Session URI, and interchanges the XML From and To elements.

EPSS

Процентиль: 47%
0.00238
Низкий

5.7 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-287