Filtered by vendor Totemo Subscriptions
Filtered by product Totemomail Subscriptions
Total 5 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-7918 1 Totemo 1 Totemomail 2024-11-21 5.4 Medium
An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.
CVE-2018-15513 1 Totemo 1 Totemomail 2024-11-21 N/A
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.
CVE-2018-15512 1 Totemo 1 Totemomail 2024-11-21 N/A
Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
CVE-2018-15511 1 Totemo 1 Totemomail 2024-11-21 N/A
Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
CVE-2018-15510 1 Totemo 1 Totemomail 2024-11-21 N/A
Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.