Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface through improper handling of the _s (breadcrumb) parameter. The application accepts state-changing requests via the GET method and automatically processes base64-encoded commands queued in the _s parameter immediately after administrator authentication. Attackers can craft malicious URLs that, when clicked by administrators, execute arbitrary administrative actions upon login without further user interaction, including creating rogue administrator accounts or modifying critical server configurations.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Axigen Mail Server 安全漏洞
Vulnerability Description
Axigen Mail Server是Axigen公司的一款邮件服务器软件。 Axigen Mail Server 10.5.57之前版本和10.6.26版本之前的10.6.x版本存在安全漏洞,该漏洞源于WebAdmin界面通过不当处理_s参数存在跨站请求伪造,攻击者可构造恶意URL,在管理员点击登录后执行任意管理操作。
CVSS Information
N/A
Vulnerability Type
N/A