MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled.
2019-01-16T16:29:00.243
2024-11-21T02:40:14.090
Modified
CVSSv3.0: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mailenable | mailenable | < 8.60 | Yes |