Vulnerabilities (CVE)

Filtered by vendor Totemo Subscribe
Filtered by product Totemomail
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-7918 1 Totemo 1 Totemomail 2023-12-10 5.5 MEDIUM 5.4 MEDIUM
An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.
CVE-2018-15512 1 Totemo 1 Totemomail 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
CVE-2018-15510 1 Totemo 1 Totemomail 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
CVE-2018-15511 1 Totemo 1 Totemomail 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
CVE-2018-15513 1 Totemo 1 Totemomail 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.