CVE-2000-0911IMP vulnerability

2 documents2 sources
Severity
5.0MEDIUMNVD
EPSS
0.5%
top 33.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 19
Latest updateApr 30

Description

IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDhorde/imp2.0, 2.2+1

Patches

🔴Vulnerability Details

1
GHSA
GHSA-vg6v-439r-vr4v: IMP 22022-04-30