Vulnerabilities > CVE-2013-4790 - Credentials Management vulnerability in Open-Xchange Appsuite

047910
CVSS 3.5 - LOW
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE

Summary

Open-Xchange AppSuite before 7.0.2 rev14, 7.2.0 before rev11, 7.2.1 before rev10, and 7.2.2 before rev9 relies on user-supplied data to predict the IMAP server hostname for an external domain name, which allows remote authenticated users to discover e-mail credentials of other users in opportunistic circumstances via a manual-mode association of a personal e-mail address with the hostname of a crafted IMAP server.

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/122635/openxchange-inject.txt
idPACKETSTORM:122635
last seen2016-12-05
published2013-08-01
reporterMartin Braun
sourcehttps://packetstormsecurity.com/files/122635/Open-Xchange-AppSuite-7.2.2-Phishing-Data-Injection.html
titleOpen-Xchange AppSuite 7.2.2 Phishing / Data Injection