First published: Tue Feb 06 2018(Updated: )
Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1.
Credit: vulnerability@kaspersky.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kaspersky Secure Mail Gateway | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6288 is classified as a high severity vulnerability due to the potential for administrative account takeover.
The recommended fix for CVE-2018-6288 is to apply the latest security patches provided by Kaspersky for Secure Mail Gateway version 1.1.
CVE-2018-6288 enables a Cross-site Request Forgery (CSRF) attack, allowing unauthorized actions to be performed by an attacker.
Kaspersky Secure Mail Gateway version 1.1 is the only version affected by CVE-2018-6288.
Exploiting CVE-2018-6288 can lead to unauthorized administrative access, potentially compromising sensitive email communications.