CVE-2023-4595: Insertion of Sensitive Information into Externally-Accessible File or Directory in BVRP Software SLmail
An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of the following parameters to the end of the URL: %00 %0a, %20, %2a, %a0, %aa, %c0 and %ca.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-4595?
CVE-2023-4595 is a vulnerability that allows a remote user to retrieve sensitive information stored on the server.
How does CVE-2023-4595 work?
CVE-2023-4595 works by allowing a remote user to append certain parameters to the end of a file or directory path, which then exposes sensitive information.
What is the severity of CVE-2023-4595?
CVE-2023-4595 has a severity rating of 7.5, which is considered high.
Which software is affected by CVE-2023-4595?
The Seattlelab Slmail software version 5.5.0.4433 is affected by CVE-2023-4595.
How do I fix CVE-2023-4595?
To fix CVE-2023-4595, it is recommended to apply the latest security patches or updates provided by the software vendor.