Impact
The vulnerability is a missing Host header validation and lack of throttling for failed administrator sign‑ins in the hMailServer REST API, allowing an attacker to perform a DNS‑rebinding attack and brute‑force the administrator password from within a victim’s own browser. Successful brute‑force yields full administrative control over the mail server, potentially exposing all hosted mailboxes and allowing further lateral movement.
Affected Systems
The affected product is Progressive Robot Ltd’s hMailServer, versions 6.0.0 through 6.3.5. These versions run the REST listener with no Host header filtering and no login attempt throttling.
Risk and Exploitability
With a CVSS score of 7.5 this issue presents a moderate to high severity. The EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, relying on DNS rebinding to trick a browser originating on the mail server into sending requests directly to the loopback‑bound REST listener. This allows the attacker to send authenticated requests at full speed, gaining administrative privileges if the password is guessed successfully. The lack of account lockout or delay mechanisms means that brute‑forcing can be performed rapidly until success.
OpenCVE Enrichment