CVE-2022-28218
26.04.2022, 18:15
An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-factor authentication (2FA).Enginsight
Vendor | Product | Version |
---|---|---|
ciphermail | webmail_messenger | 1.1.1 ≤ 𝑥 < 4.2.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References