Date: Tue, 7 Jul 2015 14:18:27 +0200 From: Stefan Castille <stefan.castille@...nierdigital.se> To: <oss-security@...ts.openwall.com> Subject: CVE request CSRF in sogo Hej, I would like to request a CVE for a CSRF vulnerability in sogo, the open groupware platform. site: www.sogo.nu Previously requested: no Type: CSRF Affected versions: up till 2.3.0 (current) Description: The application does not protect against CSRF attacks for most of its functions. Only change password seems to have some protection. But functions such as sending email, setting up mail forward and everything else is not protected. http://www.sogo.nu/bugs/view.php?id=3246 Stefan Castille
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.