CVE-2020-7918

Publication date

2020-03-27 13:43:49

Family

mitre

State

PUBLISHED

Description

An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.