Improper access control in MDaemon - #VU335
Published: August 20, 2016
MDaemon
Detailed vulnerability description
The vulnerability allows a remote attacker to gain administrative privileges within the application.
The vulnerability exists due to unknown error. A remote attacker can unauthorized access to administrative settings and users’ emails.
Successful exploitation of this vulnerability will allow a remote attacker to reconfigure the messaging server and read emails of all server users.
Remediation
This vulnerability is fixed in the following versions:
- MDaemon 11.0.4
- MDaemon 12.0.5 BBE
- MDaemon 12.0.5
- MDaemon 12.5.8
- MDaemon 13.0.2