CVE-2018-6562

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
18/05/2018
Last modified:
03/10/2019

Description

totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user sessions and encryption key material via a JSONP hijacking attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:totemo:totemomail_encryption_gateway:*:*:*:*:*:*:*:* 6.0.0_b567 (excluding)