Impact
The flaw is an uncontrolled eviction of older entries in the shared browser session table of the REST API. When the table reaches capacity it removes the least‑recently used entry regardless of the owning account, and it imposes no upper bound on how many sessions a single account can create. As a result, a user with valid credentials can flood the server with logins using their own mailbox password, keep the table full, and cause any idle session belonging to other users—including webmail, administrative, or support consoles—to be evicted. This produces a denial‑of‑service condition by forcing other users out of context and potentially disrupting ongoing operations.
Affected Systems
The vulnerability exists in Progressive Robot Ltd’s hMailServer, affecting all installations of versions 6.2.28 through 6.3.5. The issue is specific to the REST API endpoint for managing browser sessions, which is shared among all accounts, the server administrator, and support sessions.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires remote authenticated access to the REST API and repeated POST requests to /api/v1/session. Once the attacker has a valid account, they can maintain a flooded session table by repeatedly signing in, thereby expiring other users’ idle sessions. No public exploits are documented, but the inherent nature of the flaw allows an attacker in possession of any valid user credential to cause service interruption.
OpenCVE Enrichment