Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers to modify arbitrary settings and perform unauthorized actions as an arbitrary user, as demonstrated using a settings action in the SRC attribute of an IMG element in an HTML e-mail.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
@Mail WebMail 'util.pl'跨站请求伪造漏洞
Vulnerability Description
@Mail WebMail 4.51中的util.pl存在跨站请求伪造(CSRF)漏洞,远程攻击者可以作为任意用户来修改任意设置并执行未授权操作,如通过HTML电子邮件中的IMG元素的SRC属性中的设置操作。
CVSS Information
N/A
Vulnerability Type
N/A