PT-2021-18208 · Sydent · Sydent
Richvdh
·
Published
2021-04-15
·
Updated
2022-08-03
·
CVE-2021-29432
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Sydent versions prior to 4469d1d
Description:
A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address, potentially constructing plausible phishing emails.
Recommendations:
For versions prior to 4469d1d, update to a version that includes the fixes, such as 4469d1d, 6b405a8, or 65a6e91. Note that if the default email templates have been locally modified, they must also be updated to prevent exploitation. As a temporary workaround, consider restricting access to the email functionality in Sydent until the update can be applied.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sydent