5.1

CVE-2007-0652

Cross-site request forgery (CSRF) vulnerability in MailEnable Professional before 2.37 allows remote attackers to modify arbitrary configurations and perform unauthorized actions as arbitrary users via a link or IMG tag.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MailenableMailenable Professional Version1.0.004
MailenableMailenable Professional Version1.0.005
MailenableMailenable Professional Version1.0.006
MailenableMailenable Professional Version1.0.007
MailenableMailenable Professional Version1.0.008
MailenableMailenable Professional Version1.0.009
MailenableMailenable Professional Version1.0.010
MailenableMailenable Professional Version1.0.011
MailenableMailenable Professional Version1.0.012
MailenableMailenable Professional Version1.0.013
MailenableMailenable Professional Version1.0.014
MailenableMailenable Professional Version1.0.015
MailenableMailenable Professional Version1.0.016
MailenableMailenable Professional Version1.0.017
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.05% 0.862
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.