CVE-2007-4073: Medium severity Tincan Webbler Cms vulnerability
Webbler CMS before 3.1.6 does not properly restrict use of "mail a friend" forms, which allows remote attackers to send arbitrary amounts of forged e-mail. NOTE: this could be leveraged for spam or phishing attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4073?
CVE-2007-4073 is considered a medium severity vulnerability as it allows unauthorized use of 'mail a friend' forms.
How do I fix CVE-2007-4073?
To fix CVE-2007-4073, upgrade Webbler CMS to version 3.1.6 or later to ensure proper restriction of the email functionality.
What impact does CVE-2007-4073 have on Webbler CMS?
CVE-2007-4073 allows attackers to send an arbitrary number of forged emails, which can be exploited for spam or phishing campaigns.
Is CVE-2007-4073 still a risk if I use a later version than 3.1.4?
No, using Webbler CMS version 3.1.6 or later mitigates the risk associated with CVE-2007-4073.
Are there any workarounds for CVE-2007-4073 if I cannot upgrade?
If you cannot upgrade, consider disabling the 'mail a friend' feature temporarily to prevent potential abuse.