685
VMScore

CVE-2018-6563

Published: 20/06/2018 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway prior to 6.0.0_Build_371 allow remote malicious users to hijack the authentication of users for requests that (1) change user settings, (2) send emails, or (3) change contact information by leveraging lack of an anti-CSRF token.

Vulnerable Product Search on Vulmon Subscribe to Product

totemo encryption gateway

Exploits

<!-- ################################################################################ # # COMPASS SECURITY ADVISORY # wwwcompass-securitycom/research/advisories/ # ################################################################################ # # Product: totemomail Encryption Gateway # Vendor: totemo AG # CSNC ID: CSNC-2018-003 ...
Totemomail Encryption Gateway version 600_Build_371 suffers from a cross site request forgery vulnerability ...