Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-26430
HistoryAug 02, 2023 - 1:15 p.m.

Code injection

2023-08-0213:15:00
PRIOn knowledge base
www.prio-n.com
4
code injection
sieve
mail-filter rules
unauthorized access
sanitization
exploits

4.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.7%

Attackers with access to user accounts can inject arbitrary control characters to SIEVE mail-filter rules. This could be abused to access SIEVE extension that are not allowed by App Suite or to inject rules which would break per-user filter processing, requiring manual cleanup of such rules. We have added sanitization to all mail-filter APIs to avoid forwardning control characters to subsystems. No publicly available exploits are known.

4.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.7%

Related for PRION:CVE-2023-26430