PT-2007-2108 · Mailenable · Mailenable Professional
Publicado
2007-02-15
·
Atualizado
2018-10-16
·
CVE-2007-0652
CVSS v2.0
5.1
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
MailEnable Professional versions prior to 2.37
Description
A cross-site request forgery issue allows remote attackers to modify arbitrary configurations and perform unauthorized actions as arbitrary users via a link or IMG tag.
Recommendations
For MailEnable Professional versions prior to 2.37, update to version 2.37 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mailenable Professional