Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CommuniGate Pro Webmail会话劫持漏洞
Vulnerability Description
CommuniGate Pro 3.1到4.0.6版本将会话ID发送给图像HTTP请求的参照字段。远程攻击者借助带IMG标签的电子邮件劫持邮件会话,该标签引用了捕获参照页的恶意URL。
CVSS Information
N/A
Vulnerability Type
N/A