PT-2000-1649 · Alt N Technologies · Mdaemon
Published
2000-10-20
·
Updated
2017-10-10
·
CVE-2000-0716
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MDaemon version 2.8
Description
The issue concerns the WorldClient email client in MDaemon, where the session ID is included in the referer field of an HTTP request when a user clicks on a URL. This allows the visited website to potentially hijack the session ID and access the user's email.
Recommendations
For MDaemon version 2.8, consider restricting access to external URLs from within the email client to minimize the risk of session ID hijacking until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mdaemon