An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-03-27T13:43:49

Updated: 2020-03-27T13:43:49

Reserved: 2020-01-22T00:00:00


Link: CVE-2020-7918

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-03-27T14:15:12.527

Modified: 2020-03-31T19:34:30.827


Link: CVE-2020-7918

JSON object: View

cve-icon Redhat Information

No data.

CWE