CVE-2017-9517: CSRF
Published Jun 8, 2017
·Updated
atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.
Affected Software
1 affected component
Atmail atmail<=7.8.0.1
Event History
Jun 8, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9517?
CVE-2017-9517 is classified as a medium severity vulnerability due to its ability to allow unauthorized CSV file uploads.
2
How do I fix CVE-2017-9517?
To fix CVE-2017-9517, upgrade Atmail to version 7.8.0.2 or later.
3
What types of attacks does CVE-2017-9517 enable?
CVE-2017-9517 enables Cross-Site Request Forgery (CSRF) attacks that can lead to unauthorized user imports.
4
Which versions of Atmail are affected by CVE-2017-9517?
CVE-2017-9517 affects all versions of Atmail prior to 7.8.0.2.
5
Can CVE-2017-9517 be exploited remotely?
Yes, CVE-2017-9517 can be exploited remotely by an attacker capable of leveraging CSRF.