PT-2018-17637 · Totemomail · Totemomail Encryption Gateway

Nicolas Heiniger

·

Publicado

2018-06-20

·

Atualizado

2018-10-09

·

CVE-2018-6563

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions totemomail Encryption Gateway versions prior to 6.0.0 Build 371
Description The issue allows remote attackers to hijack user authentication for various requests, including changing user settings, sending emails, or modifying contact information, by exploiting the lack of an anti-CSRF token.
Recommendations For versions prior to 6.0.0 Build 371, update to version 6.0.0 Build 371 or later to resolve the issue.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-6563

Produtos afetados

Totemomail Encryption Gateway