mailcow是一个邮件服务器套件。 mailcow 2024-07之前版本存在安全漏洞,该漏洞源于经过身份验证的管理员用户可以将JavaScript有效载荷注入中继主机配置,从而使攻击者能够在用户浏览器的上下文中执行任意脚本,导致数据被盗或进一步利用受影响的系统。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mailcow | mailcow-dockerized | < 2024-07 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-41959 | 7.6 HIGH | Cross-site Scripting (XSS) via API Logs in mailcow: dockerized |
| CVE-2024-41958 | 6.6 MEDIUM | Two-Factor Authentication (2FA) Bypass in mailcow: dockerized |
No comments yet