Back to search
CVE-2017-5930
Published: Mar 20, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[postfixadmin-devel] 20170204 Security hole in AliasHandler
mailing-list
x_refsource_MLIST
96142
vdb-entry
x_refsource_BID
openSUSE-SU-2017:0488
vendor-advisory
x_refsource_SUSE
[oss-security] 20170207 Re: CVE request: PostfixAdmin allows to delete protected aliases
mailing-list
x_refsource_MLIST
https://github.com/postfixadmin/postfixadmin/pull/23
x_refsource_CONFIRM
[oss-security] 20170209 Re: CVE request: PostfixAdmin allows to delete protected aliases
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now