Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero permissions can bypass access control checks and gain unauthorized access to the SSL Certificates management endpoint (page=sslcerts). This allows the attacker to view, download, upload, and delete SSL certificate files, despite lacking the necessary privileges to access the Security & Filtering section.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Axigen Mail Server 安全漏洞
Vulnerability Description
Axigen Mail Server是Axigen公司的一款邮件服务器软件。 Axigen Mail Server 10.5.57之前版本存在安全漏洞,该漏洞源于WebAdmin界面存在访问控制不当,零权限的委派管理员账户可绕过访问控制检查,未经授权访问SSL证书管理端点。
CVSS Information
N/A
Vulnerability Type
N/A