PT-2015-6073 · Synametrics Technologies · Xeams
Marlow Tannhauser
·
Published
2015-05-20
·
Updated
2016-12-03
·
CVE-2015-3141
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Synametrics Technologies Xeams versions 4.5 Build 5755 and earlier
Description
The issue allows remote attackers to hijack the authentication of administrators for requests, such as creating an SMTP domain or a user, via a request to "FrontController". It also enables cross-site scripting (XSS) attacks through various parameters, including the
domainname parameter when creating a new SMTP domain configuration, the txtRecipient parameter when creating a new forwarder, the popFetchServer, popFetchUser, or popFetchRecipient parameters when creating a new POP3 Fetcher account, and the Smtp HELO domain in the Advanced Server Configuration.Recommendations
For Synametrics Technologies Xeams versions 4.5 Build 5755 and earlier, consider disabling access to the "FrontController" endpoint until a patch is available. Restrict the use of parameters
domainname, txtRecipient, popFetchServer, popFetchUser, popFetchRecipient, and the Smtp HELO domain in the Advanced Server Configuration to minimize the risk of exploitation. Avoid using these parameters in the affected API endpoint until the issue is resolved.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xeams