RSS   Vulnerabilities for 'Totemomail'   RSS

2020-03-27
 
CVE-2020-7918

CWE-639
 

 
An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.

 
2019-08-30
 
CVE-2018-15513

CWE-284
 

 
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.

 
 
CVE-2018-15512

CWE-79
 

 
Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.

 
 
CVE-2018-15511

CWE-79
 

 
Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.

 
 
CVE-2018-15510

CWE-79
 

 
Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.

 

 >>> Vendor: Totemo 2 Products
Encryption gateway
Totemomail


Copyright 2024, cxsecurity.com

 

Back to Top