SB2018032003 - Information disclosure in SquirrelMail



SB2018032003 - Information disclosure in SquirrelMail

Published: March 20, 2018

Security Bulletin ID SB2018032003
Severity
Medium
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Path traversal (CVE-ID: CVE-2018-8741)

The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information on the target system.

The weakness exists due to input validation flaw in 'Deliver.class.php'. A remote attacker can upload a file with a specially crafted filename containing directory traversal characters (e.g., '../'), cause the system to attach arbitrary files to an email message with the privileges of the target PHP process and obtain or delete arbitrary files with the privileges of the target PHP process.

Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.