Vulnerability Description
ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Administration dashboard. When using admin/user credentials, if the admin/user admin opens a website with the malicious page that will run the CSRF.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Argosoft | Mail Server | 1.8.8.9 |
Related Weaknesses (CWE)
References
- https://github.com/V1n1v131r4/CSRF-on-ArGoSoft-Mail-Server/blob/master/README.mdExploitThird Party Advisory
- https://github.com/V1n1v131r4/CSRF-on-ArGoSoft-Mail-Server/blob/master/README.mdExploitThird Party Advisory
FAQ
What is CVE-2020-23824?
CVE-2020-23824 is a vulnerability with a CVSS score of 8.8 (HIGH). ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Administration dashboard. When using admin/user credent...
How severe is CVE-2020-23824?
CVE-2020-23824 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-23824?
Check the references section above for vendor advisories and patch information. Affected products include: Argosoft Mail Server.