CVE-2018-8741: Path Traversal
A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the attlocalname field in Deliver.class.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8741?
CVE-2018-8741 has a medium severity rating due to its potential for file exfiltration and manipulation.
How do I fix CVE-2018-8741?
To fix CVE-2018-8741, upgrade SquirrelMail to a more secure version that addresses the directory traversal vulnerability.
What systems are affected by CVE-2018-8741?
CVE-2018-8741 affects SquirrelMail version 1.4.22 running on Debian Linux 7.0 and 8.0.
Can CVE-2018-8741 be exploited remotely?
Yes, CVE-2018-8741 can be exploited remotely by an authenticated attacker with access to the SquirrelMail application.
What impact does CVE-2018-8741 have on data integrity?
CVE-2018-8741 can lead to unauthorized access to sensitive files, which compromises data integrity and confidentiality.