vendor:
Mail-SeCure Suite
by:
John Petrusa
7,2
CVSS
HIGH
Access control failure
264
CWE
Product Name: Mail-SeCure Suite
Affected Version From: All Mail-SeCure versions prior to 3.70.
Affected Version To: Mail-SeCure 3.70 (revision Sep. 2013)
Patch Exists: Yes
Related CWE: CVE-2013-4987
CPE: a:pineapp:mail-secure
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
PinApp Mail-SeCure Access Control Failure
A security vulnerability was discovered in PineApp [1] Mail-SeCure Suite [2], allowing a non-privileged attacker to get a root shell by sending a specially crafted command from the Mail-SeCure console. A valid user account is needed to launch the attack, so this is a privileged escalation vulnerability that can be exploited locally only.
Mitigation:
Upgrade to Mail-SeCure version 3.70 or later.