PT-2007-4037 · Intermesh · Group-Office
Publicado
2007-05-16
·
Atualizado
2011-03-08
·
CVE-2007-2720
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Group-Office versions prior to 2.16-13
Description
The issue allows remote attackers to obtain sensitive information via certain requests for specific API endpoints, including "message.php" and "messages.php" in the modules/email/ directory, due to improper validation of user IDs, specifically the
user id variable.Recommendations
For versions prior to 2.16-13, update to version 2.16-13 or later to resolve the issue. As a temporary workaround, consider restricting access to the "message.php" and "messages.php" endpoints in the modules/email/ directory to minimize the risk of exploitation. Avoid using the
user id variable in these affected API endpoints until the issue is resolved.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Group-Office