Security Advisory
CVE-2025-43918
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
SSL.com before 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a trusted TLS certificate may be issued for the domain name of a requesters email address, even when the requester does not otherwise establish administrative control of that domain.