Vulnerabilities > Reddoxx

DATE CVE VULNERABILITY TITLE RISK
2020-11-18 CVE-2020-26554 Cross-site Scripting vulnerability in Reddoxx Maildepot 2033
REDDOXX MailDepot 2033 (aka 2.3.3022) allows XSS via an incoming HTML e-mail message.
network
low complexity
reddoxx CWE-79
6.1
2020-10-06 CVE-2019-19200 Incorrect Authorization vulnerability in Reddoxx Maildepot 2032
REDDOXX MailDepot 2032 2.2.1242 allows authenticated users to access the mailboxes of other users.
network
low complexity
reddoxx CWE-863
8.8
2020-10-02 CVE-2019-19199 Insufficient Session Expiration vulnerability in Reddoxx Maildepot 2032
REDDOXX MailDepot 2032 SP2 2.2.1242 has Insufficient Session Expiration because tokens are not invalidated upon a logout.
network
high complexity
reddoxx CWE-613
7.4