A CSRF issue was discovered in LWsystems Benno MailArchiv 2.10.1.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://wiki.benno-mailarchiv.de/doku.php | vendor advisory |
https://blog.sebastianschmitt.eu/security/xsrf-in-benno-mailarchiv-web-app-benno-web-2-10-2-cve-2023-38348/ | third party advisory exploit |