Postfixadmin · Postfix Admin · CVE-2017-5930
**Name of the Vulnerable Software and Affected Versions**
PostfixAdmin versions prior to 3.0.2
**Description**
The issue concerns a missing permission check in the AliasHandler component, allowing remote authenticated domain admins to delete protected aliases. This can be achieved by manipulating the `delete` parameter to the `/delete.php` API endpoint.
**Recommendations**
For versions prior to 3.0.2, update to version 3.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the `/delete.php` endpoint for domain admins to minimize the risk of exploitation.