Products
Kiteworks Totemomail
- 7.x
- 8.x before 8.3.0
Source
cve@mitre.org
Tags
CVE-2024-28064 details
Published : May 18, 2024, 10:15 p.m.
Last Modified : May 18, 2024, 10:15 p.m.
Last Modified : May 18, 2024, 10:15 p.m.
Description
Kiteworks Totemomail 7.x and 8.x before 8.3.0 allows /responsiveUI/EnvelopeOpenServlet messageId directory traversal for unauthenticated file read and delete operations (with displayLoginChunkedImages) and write operations (with storeLoginChunkedImages).
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
References
URL | Source |
---|---|
https://www.objectif-securite.ch/advisories/totemomail-path-traversal.txt | cve@mitre.org |
This website uses the NVD API, but is not approved or certified by it.