VulnerabilityModified
CVE-2017-5930
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.
LOW 2.7EPSS 15.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.
- CVSS 3.1
- 2.7 LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 14.95% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- opensuse/leap · postfixadmin project/postfixadmin
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-updates/2017-02/msg00076.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2017/02/08/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/02/09/1Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/96142Third Party Advisory, VDB Entry, Vendor Advisory
- https://github.com/postfixadmin/postfixadmin/blob/postfixadmin-3.0.2/CHANGELOG.TXTRelease Notes, Third Party Advisory
- https://github.com/postfixadmin/postfixadmin/pull/23Patch, Third Party Advisory
- https://sourceforge.net/p/postfixadmin/mailman/message/35646827/Patch, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2017-02/msg00076.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2017/02/08/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/02/09/1Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/96142Third Party Advisory, VDB Entry, Vendor Advisory
- https://github.com/postfixadmin/postfixadmin/blob/postfixadmin-3.0.2/CHANGELOG.TXTRelease Notes, Third Party Advisory
- https://github.com/postfixadmin/postfixadmin/pull/23Patch, Third Party Advisory
- https://sourceforge.net/p/postfixadmin/mailman/message/35646827/Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.