Описание
SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mailing lists.
Ссылки
- Third Party Advisory
- ExploitRelease NotesVendor Advisory
- Third Party Advisory
- ExploitRelease NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 16.0.6345 (включая) до 16.3.6985 (исключая)
cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*
EPSS
Процентиль: 65%
0.00482
Низкий
8.2 High
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-798
Связанные уязвимости
github
больше 3 лет назад
SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users? emails and file attachments. It was also possible to interact with mailing lists.
EPSS
Процентиль: 65%
0.00482
Низкий
8.2 High
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-798