ZDI-CAN-5594: Trend Micro Encryption for Email Gateway formChangePass username SQL Injection Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Trend Micro Encryption for Email Gateway. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the formChangePass class. When parsing the username parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this in conjunction with other vulnerabilities to disclose sensitive information under the context of the database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-5594?
The severity of ZDI-CAN-5594 is considered high due to its potential for sensitive information disclosure.
How do I fix ZDI-CAN-5594?
To fix ZDI-CAN-5594, apply the latest patches and updates provided by Trend Micro for Encryption for Email Gateway.
Who is affected by ZDI-CAN-5594?
ZDI-CAN-5594 affects installations of Trend Micro Encryption for Email Gateway that are vulnerable to exploitation.
What type of vulnerability is ZDI-CAN-5594?
ZDI-CAN-5594 is a remote information disclosure vulnerability that can be exploited with bypassed authentication.
Is authentication required to exploit ZDI-CAN-5594?
Yes, authentication is required to exploit ZDI-CAN-5594, but it can be bypassed.