CVE-2013-6028 Information

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Atmail Webmail Server before 7.2 allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts (2) modify user accounts (3) delete user accounts or (4) stop the product’s service.

Reference

http://atmail.com/changelog/ http://osvdb.org/101936 http://www.kb.cert.org/vuls/id/204950

Share on: