CVE-2017-9518: CSRF
Published Jun 8, 2017
·Updated
atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.
Affected Software
1 affected component
Atmail atmail<=7.8.0.1
Event History
Jun 8, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9518?
CVE-2017-9518 is classified as a medium severity vulnerability due to its potential impact on email security.
2
How do I fix CVE-2017-9518?
To fix CVE-2017-9518, upgrade Atmail to version 7.8.0.2 or later.
3
What type of vulnerability is CVE-2017-9518?
CVE-2017-9518 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
What systems are affected by CVE-2017-9518?
CVE-2017-9518 affects Atmail versions prior to 7.8.0.2.
5
What could an attacker do with CVE-2017-9518?
An attacker could leverage CVE-2017-9518 to change the SMTP hostname and hijack email communications.