Softnext Mail SQR Expert - Blind Server-Side Request Forgey (SSRF)
CVE-2023-48379

5.3MEDIUM

Key Information:

Vendor

Softnext

Vendor
CVE Published:
15 December 2023

What is CVE-2023-48379?

Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter within a specific function. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.

Affected Version(s)

Mail SQR Expert <= 230330

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.