漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Sensitive Information Disclosure in HTTP header
Vulnerability Description
SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.
CVSS Information
N/A
Vulnerability Type
通过GET请求中的查询字符串导致的信息暴露
Vulnerability Title
SEPPmail Secure Email Gateway & SEPPmail Cloud 信息泄露漏洞
Vulnerability Description
SEPPmail SEPPmail Secure Email Gateway & SEPPmail Cloud是瑞士SEPPmail公司的一款电子邮件安全网关系统。 SEPPmail Secure Email Gateway & SEPPmail Cloud 15.0.4.2之前版本存在信息泄露漏洞,该漏洞源于会话令牌在URL和HTTP标头中泄露,可能导致攻击者重放和劫持用户会话。
CVSS Information
N/A
Vulnerability Type
N/A