vendor:
mailcow
by:
John Page
8.8
CVSS
HIGH
CSRF
CSRF
CWE
Product Name: mailcow
Affected Version From: 0.14
Affected Version To: 0.14
Patch Exists: YES
Related CWE: CVE-2017-8928
CPE: mailcow.email, mailcow.github.io
Platforms Tested:
2017
CSRF Password Reset / Add Admin / Delete Domains in mailcow 0.14
CSRF vulnerabilities in mailcow 0.14 allow authenticated mailcow users to perform malicious actions such as resetting admin password, adding arbitrary admin, and deleting domains.
Mitigation:
Upgrade to a patched version of mailcow, or apply the patch provided in the reference.