6.4
CVSSv2

CVE-2018-7702

Published: 15/03/2018 Updated: 03/10/2019
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

SecurEnvoy SecurMail prior to 9.2.501 allows remote malicious users to spoof transmission of arbitrary e-mail messages, resend e-mail messages to arbitrary recipients, or modify arbitrary message bodies and attachments by leveraging missing authentication and authorization.

Vulnerable Product Search on Vulmon Subscribe to Product

securenvoy securmail

Exploits

SEC Consult Vulnerability Lab Security Advisory < 20180312-0 > ======================================================================= title: Multiple Critical Vulnerabilities product: SecurEnvoy SecurMail vulnerable version: 91501 fixed version: 92501 or hotfix patch "1_012018" CVE number: CVE-20 ...
SecurEnvoy SecurMail version 91501 suffers from cross site request forgery, cross site scripting, insecure direct object reference, missing authentication and authorization, and path traversal vulnerabilities ...