Cross-site request forgery (CSRF) vulnerability in util...
High severity
Unreviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Description
Published by the National Vulnerability Database
Dec 23, 2006
Published to the GitHub Advisory Database
May 1, 2022
Last updated
Jan 31, 2023
Cross-site request forgery (CSRF) vulnerability in util.pl in @mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers to modify arbitrary settings and perform unauthorized actions as an arbitrary user, as demonstrated using a settings action in the SRC attribute of an IMG element in an HTML e-mail.
References