The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in CommuniGate Pro (CGP) 6.2 suffers from a Missing XIMSS Protocol Validation attack that leads to an email spoofing attack, allowing a malicious authenticated attacker to send a message from any source email address. The attack uses an HTTP POST request to a /Session URI, and interchanges the XML From and To elements.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-01-08T05:00:00
Updated: 2024-08-05T04:57:22.989Z
Reserved: 2018-01-01T00:00:00
Link: CVE-2018-3815
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-01-08T05:29:00.290
Modified: 2024-11-21T04:06:05.423
Link: CVE-2018-3815
Redhat
No data.