2.7
CVSSv3

CVE-2017-5930

Published: 20/03/2017 Updated: 26/02/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 2.7 | Impact Score: 1.4 | Exploitability Score: 1.2
VMScore: 390
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

The AliasHandler component in PostfixAdmin prior to 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse leap 42.1

opensuse leap 42.2

postfixadmin project postfixadmin

Vendor Advisories

Debian Bug report logs - #854742 CVE-2017-5930 Package: postfixadmin; Maintainer for postfixadmin is Norman Messtorff <normes@normesorg>; Source for postfixadmin is src:postfixadmin (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 9 Feb 2017 23:21:07 UTC Severity: grave Tags: secur ...