Vulnerabilities (CVE)

Filtered by vendor Modoboa Subscribe
Total 15 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-2160 1 Modoboa 1 Modoboa 2023-12-18 N/A 9.8 CRITICAL
Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0.
CVE-2023-5689 1 Modoboa 1 Modoboa 2023-12-10 N/A 5.4 MEDIUM
Cross-site Scripting (XSS) - DOM in GitHub repository modoboa/modoboa prior to 2.2.2.
CVE-2023-5688 1 Modoboa 1 Modoboa 2023-12-10 N/A 5.4 MEDIUM
Cross-site Scripting (XSS) - DOM in GitHub repository modoboa/modoboa prior to 2.2.2.
CVE-2023-5690 1 Modoboa 1 Modoboa 2023-12-10 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.2.2.
CVE-2023-2227 1 Modoboa 1 Modoboa 2023-12-10 N/A 9.1 CRITICAL
Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.
CVE-2023-2228 1 Modoboa 1 Modoboa 2023-12-10 N/A 6.8 MEDIUM
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.1.0.
CVE-2023-0777 1 Modoboa 1 Modoboa 2023-12-10 N/A 9.8 CRITICAL
Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.
CVE-2023-0519 1 Modoboa 1 Modoboa 2023-12-10 N/A 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4.
CVE-2023-0949 1 Modoboa 1 Modoboa 2023-12-10 N/A 4.8 MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository modoboa/modoboa prior to 2.0.5.
CVE-2023-0398 1 Modoboa 1 Modoboa 2023-12-10 N/A 6.5 MEDIUM
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
CVE-2023-0438 1 Modoboa 1 Modoboa 2023-12-10 N/A 6.5 MEDIUM
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
CVE-2023-0406 1 Modoboa 1 Modoboa 2023-12-10 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
CVE-2023-0470 1 Modoboa 1 Modoboa 2023-12-10 N/A 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4.
CVE-2023-0860 1 Modoboa 1 Installer 2023-12-10 N/A 7.5 HIGH
Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4.
CVE-2019-19702 1 Modoboa 1 Modoboa-dmarc 2023-12-10 5.0 MEDIUM 7.5 HIGH
The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to perform a denial of service against the DMARC reporting functionality, such as by referencing the /dev/random file within XML documents that are emailed to the address in the rua field of the DMARC records of a domain.