Vulnerabilities > CVE-2017-5930 - Missing Authorization vulnerability in multiple products
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Metasploit
description | Postfixadmin installations between 2.91 and 3.0.1 do not check if an admin is allowed to delete protected aliases. This vulnerability can be used to redirect protected aliases to an other mail address. Eg. rewrite the postmaster@domain alias |
id | MSF:AUXILIARY/ADMIN/HTTP/PFADMIN_SET_PROTECTED_ALIAS |
last seen | 2020-06-13 |
modified | 2019-09-23 |
published | 2017-03-05 |
references | |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/admin/http/pfadmin_set_protected_alias.rb |
title | Postfixadmin Protected Alias Deletion Vulnerability |
Nessus
NASL family | SuSE Local Security Checks |
NASL id | OPENSUSE-2017-261.NASL |
description | postfixadmin was updated to 3.0.2 to fix the following issues : - PostfixAdmin 3.0.2 : - SECURITY: don |
last seen | 2020-06-05 |
modified | 2017-02-21 |
plugin id | 97281 |
published | 2017-02-21 |
reporter | This script is Copyright (C) 2017-2020 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/97281 |
title | openSUSE Security Update : postfixadmin (openSUSE-2017-261) |
code |
|
References
- http://lists.opensuse.org/opensuse-updates/2017-02/msg00076.html
- http://lists.opensuse.org/opensuse-updates/2017-02/msg00076.html
- http://www.openwall.com/lists/oss-security/2017/02/08/1
- http://www.openwall.com/lists/oss-security/2017/02/08/1
- http://www.openwall.com/lists/oss-security/2017/02/09/1
- http://www.openwall.com/lists/oss-security/2017/02/09/1
- http://www.securityfocus.com/bid/96142
- http://www.securityfocus.com/bid/96142
- https://github.com/postfixadmin/postfixadmin/blob/postfixadmin-3.0.2/CHANGELOG.TXT
- https://github.com/postfixadmin/postfixadmin/blob/postfixadmin-3.0.2/CHANGELOG.TXT
- https://github.com/postfixadmin/postfixadmin/pull/23
- https://github.com/postfixadmin/postfixadmin/pull/23
- https://sourceforge.net/p/postfixadmin/mailman/message/35646827/
- https://sourceforge.net/p/postfixadmin/mailman/message/35646827/