Описание
SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.
EPSS
Процентиль: 5%
0.00153
Низкий
Дефекты
CWE-598
Связанные уязвимости
github
14 дней назад
SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.
EPSS
Процентиль: 5%
0.00153
Низкий
Дефекты
CWE-598