PT-2020-15585 · Argosoft · Argosoft Mail Server Pro
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ArGo Soft Mail Server version 1.8.8.9
Description
The issue allows for Cross Site Request Forgery (CSRF) that can lead to remote arbitrary code execution. This is specifically related to the Administration dashboard component. When an administrator or user with admin credentials opens a malicious webpage, it can trigger the CSRF, potentially allowing for unauthorized actions.
Recommendations
For ArGo Soft Mail Server version 1.8.8.9, consider restricting access to the Administration dashboard until a fix is available. As a temporary workaround, avoid using admin/user credentials to access potentially malicious websites to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Argosoft Mail Server Pro