The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a users email account.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Emurl |
Seattle_lab_software |
2.0 (including) |
2.0 (including) |
References