An issue was discovered in MDaemon before 20.0.4. Remote Administration allows an attacker to perform a fixation of the anti-CSRF token. In order to exploit this issue, the user has to click on a malicious URL provided by the attacker and successfully authenticate into the application. Having the value of the anti-CSRF token, the attacker may trick the user into visiting his malicious page and performing any request with the privileges of attacked user.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-13948 An issue was discovered in MDaemon before 20.0.4. Remote Administration allows an attacker to perform a fixation of the anti-CSRF token. In order to exploit this issue, the user has to click on a malicious URL provided by the attacker and successfully authenticate into the application. Having the value of the anti-CSRF token, the attacker may trick the user into visiting his malicious page and performing any request with the privileges of attacked user.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T20:40:47.502Z

Reserved: 2021-02-10T00:00:00

Link: CVE-2021-27181

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-14T23:15:12.197

Modified: 2024-11-21T05:57:30.307

Link: CVE-2021-27181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.