Joruri Mail 2.1.4 and earlier does not properly manage...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Jul 5, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Apr 4, 2024
Joruri Mail 2.1.4 and earlier does not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and alter/disclose the information via unspecified vectors.
References