Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23891
HistoryApr 10, 2020 - 12:39 a.m.

Cross-site Request Forgery (CSRF)

2020-04-1000:39:18
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0.004

Percentile

73.7%

SquirrelMail is vulnerable to cross-site request forgery (CSRF). Form submissions in SquirrelMail did not implement protection against Cross-Site Request Forgery (CSRF) attacks. If a remote attacker tricked a user into visiting a malicious web page, the attacker could hijack that user’s authentication, inject malicious content into that user’s preferences, or possibly send mail without that user’s permission.

References