A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated, remote attacker to download any message from the spam quarantine by modifying browser string information. The vulnerability is due to a lack of verification of authenticated user accounts. An attacker could exploit this vulnerability by modifying browser strings to see messages submitted by other users to the spam quarantine within their company. Cisco Bug IDs: CSCvg39759, CSCvg42295.
                
            Metrics
Affected Vendors & Products
References
        History
                    Mon, 02 Dec 2024 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: cisco
Published: 2018-02-08T07:00:00
Updated: 2024-12-02T21:08:30.247Z
Reserved: 2017-11-27T00:00:00
Link: CVE-2018-0140
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-05T03:14:16.872Z
 NVD
                        NVD
                    Status : Modified
Published: 2018-02-08T07:29:01.053
Modified: 2024-11-21T03:37:35.953
Link: CVE-2018-0140
 Redhat
                        Redhat
                    No data.