PT-2015-6073 · Synametrics Technologies · Xeams

Marlow Tannhauser

·

Published

2015-05-20

·

Updated

2016-12-03

·

CVE-2015-3141

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Synametrics Technologies Xeams versions 4.5 Build 5755 and earlier
Description The issue allows remote attackers to hijack the authentication of administrators for requests, such as creating an SMTP domain or a user, via a request to "FrontController". It also enables cross-site scripting (XSS) attacks through various parameters, including the domainname parameter when creating a new SMTP domain configuration, the txtRecipient parameter when creating a new forwarder, the popFetchServer, popFetchUser, or popFetchRecipient parameters when creating a new POP3 Fetcher account, and the Smtp HELO domain in the Advanced Server Configuration.
Recommendations For Synametrics Technologies Xeams versions 4.5 Build 5755 and earlier, consider disabling access to the "FrontController" endpoint until a patch is available. Restrict the use of parameters domainname, txtRecipient, popFetchServer, popFetchUser, popFetchRecipient, and the Smtp HELO domain in the Advanced Server Configuration to minimize the risk of exploitation. Avoid using these parameters in the affected API endpoint until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-3141

Affected Products

Xeams