Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Tue, 7 Jul 2015 14:18:27 +0200
From: Stefan Castille <stefan.castille@...nierdigital.se>
To: <oss-security@...ts.openwall.com>
Subject: CVE request CSRF in sogo

Hej,

I would like to request a CVE for a CSRF vulnerability in sogo, the open
groupware platform.

site: www.sogo.nu
Previously requested: no
Type: CSRF
Affected versions: up till 2.3.0 (current)
Description: The application does not protect against CSRF attacks for
most of its functions. Only change password seems to have some
protection. But functions such as sending email, setting up mail forward
and everything else is not protected.

http://www.sogo.nu/bugs/view.php?id=3246

Stefan Castille

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.