CVE-2018-7701: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) delete e-mail messages via a delete action in a request to secmail/getmessage.exe or (2) spoof arbitrary users and reply to their messages via a request to secserver/securectrl.exe.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7701?
CVE-2018-7701 has been classified as a critical vulnerability due to its potential to allow unauthorized actions on behalf of users.
How do I fix CVE-2018-7701?
To fix CVE-2018-7701, upgrade SecurEnvoy SecurMail to version 9.2.501 or later.
What types of attacks does CVE-2018-7701 allow?
CVE-2018-7701 enables remote attackers to perform cross-site request forgery attacks, such as deleting email messages or spoofing user identities.
Which versions of SecurMail are affected by CVE-2018-7701?
SecurEnvoy SecurMail versions prior to 9.2.501 are affected by CVE-2018-7701.
What is the nature of the vulnerabilities in CVE-2018-7701?
CVE-2018-7701 consists of multiple cross-site request forgery vulnerabilities that can compromise user authentication.