PT-2020-19846 · Totemo · Totemo Totemomail

Published

2020-03-27

·

Updated

2020-03-31

·

CVE-2020-7918

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions totemo totemomail version 7.0.0
Description The issue is related to an insecure direct object reference in the webmail component, allowing an authenticated remote user to read and modify mail folder names of other users via enumeration.
Recommendations For totemo totemomail version 7.0.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7918

Affected Products

Totemo Totemomail