Impact
SEPPmail Secure Email Gateway and SEPPmail Cloud expose session tokens in the URL and HTTP headers before version 15.0.4.2, allowing an attacker to replay and hijack a user session within the GINA web portal. The vulnerability is an instance of CWE‑598, where an insecure mechanism inadvertently reveals sensitive information. An attacker who gains access to the token can impersonate the legitimate user, potentially accessing confidential data or controlling the account.
Affected Systems
SEPPmail Secure Email Gateway and SEPPmail Cloud customers running any version older than 15.0.4.2 are vulnerable. The issue affects the GINA web portal component of both products.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, yet the EPSS score is below 1% and the vulnerability is not currently listed in the CISA KEV catalog, suggesting limited publicly known exploitation. The attack vector is likely a network attacker able to capture HTTP traffic or view browser URLs, which then can replay the disclosed session token. Exploitation requires intercepting or observing the HTTP request containing the token and re‑sending it to gain unauthorized access.
OpenCVE Enrichment