CVE-2023-4593: Path Traversal in BVRP Software SLmail
Path traversal vulnerability whose exploitation could allow an authenticated remote user to bypass SecurityManager's intended restrictions and list a parent directory via any filename, such as a multiple ..%2F value affecting the 'dodoc' parameter in the /MailAdmindll.htm file.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-4593?
CVE-2023-4593 is a path traversal vulnerability in BVRP Software SLmail that allows an authenticated remote user to bypass intended restrictions and list a parent directory via the 'dodoc' parameter in the /MailAdmin_dll.htm file.
How does CVE-2023-4593 affect Seattlelab Slmail?
CVE-2023-4593 affects Seattlelab Slmail version 5.5.0.4433, allowing authenticated remote users to exploit the path traversal vulnerability.
Is Microsoft Windows vulnerable to CVE-2023-4593?
No, Microsoft Windows is not vulnerable to CVE-2023-4593.
What is the severity of CVE-2023-4593?
CVE-2023-4593 has a severity score of 6.5, considered medium.
How can I fix CVE-2023-4593?
To fix CVE-2023-4593, it is recommended to update Seattlelab Slmail to a non-vulnerable version provided by the vendor.