vendor:
WebMail Pro ASP.NET
by:
Mehmet Ince
7,5
CVSS
HIGH
Sensitive Information disclosure
611
CWE
Product Name: WebMail Pro ASP.NET
Affected Version From: AfterLogic WebMail Pro ASP.NET < 6.2.7
Affected Version To: AfterLogic WebMail Pro ASP.NET < 6.2.7
Patch Exists: Yes
Related CWE: N/A
CPE: a:afterlogic:webmail_pro_asp.net
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
AfterLogic WebMail Pro ASP.NET Administrator Account Takover via XXE Injection
It seems that /webmail/spellcheck.aspx?xml= endpoint takes XML request as an parameter and parse it with XML entities. By abusing XML entities attackers can read Web.config file as well as settings.xml that contains administrator account credentials in plain-text.
Mitigation:
Update to AfterLogic WebMail Pro ASP.NET 6.2.7