Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22990
HistoryApr 10, 2020 - 12:11 a.m.

Dynamic Variable Evaluation

2020-04-1000:11:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.277 Low

EPSS

Percentile

96.8%

SquirrelMail is vulnerable to Dynamic variable evaluation. Users who have an account on a SquirrelMail server and are logged in could use this flaw to overwrite variables which may allow them to read or write other users’ preferences or attachments.

References