Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 15.0.4
affected
Description
SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information.
Problem types
CWE-497 Exposure of sensitive system information to an unauthorized control sphere
Product status
Any version before 15.0.4
References
downloads.seppmail.com/extrelnotes/150/ERN15.0.html