漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Local File Inclusion (LFI) and Arbitrary File Deletion
Vulnerability Description
SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows remote attackers to read arbitrary local files and trigger deletion of files in the targeted directory with the privileges of the api.app process.
CVSS Information
N/A
Vulnerability Type
文件名或路径的外部可控制
Vulnerability Title
SEPPmail Secure Email Gateway 安全漏洞
Vulnerability Description
SEPPmail Secure Email Gateway是德国SEPPmail公司的一个电子邮件安全网关。 SEPPmail Secure Email Gateway 15.0.4之前版本存在安全漏洞,该漏洞源于/api.app/attachment/preview中identifier参数存在未经身份验证的路径遍历,可能导致远程攻击者读取任意本地文件并触发文件删除。
CVSS Information
N/A
Vulnerability Type
N/A