Vulnerabilities > CVE-2018-7702 - Missing Authorization vulnerability in Securenvoy Securmail

047910
CVSS 9.1 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
securenvoy
CWE-862
critical
exploit available

Summary

SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e-mail messages to arbitrary recipients, or modify arbitrary message bodies and attachments by leveraging missing authentication and authorization.

Vulnerable Configurations

Part Description Count
Application
Securenvoy
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionSecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities. CVE-2018-7701,CVE-2018-7702,CVE-2018-7703,CVE-2018-7704,CVE-2018-7705,CVE-2018-7706,CVE-2018-7707. W...
fileexploits/aspx/webapps/44285.txt
idEDB-ID:44285
last seen2018-05-24
modified2018-03-13
platformaspx
port
published2018-03-13
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/44285/
titleSecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/146732/SA-20180312-0.txt
idPACKETSTORM:146732
last seen2018-03-23
published2018-03-12
reporterWolfgang Ettlinger
sourcehttps://packetstormsecurity.com/files/146732/SecurEnvoy-SecurMail-9.1.501-XSS-CSRF-Traversal.html
titleSecurEnvoy SecurMail 9.1.501 XSS / CSRF / Traversal