mailcow是一个邮件服务器套件。 mailcow 2024-07之前版本存在安全漏洞,该漏洞源于允许经过身份验证的攻击者绕过2FA保护,从而允许未经授权访问其他使用2FA保护的帐户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mailcow | mailcow-dockerized | < 2024-07 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | This is a small proof of concept for CVE-2024-41958 | https://github.com/OrangeJuiceHU/CVE-2024-41958-PoC | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-41959 | 7.6 HIGH | Cross-site Scripting (XSS) via API Logs in mailcow: dockerized |
| CVE-2024-41960 | 3.8 LOW | Cross-site Scripting (XSS) via Relay Hosts Configuration in mailcow: dockerized |
No comments yet