The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a users email account.
Affected Software
| Name |
Vendor |
Start Version |
End Version |
| Emurl |
Seattle_lab_software |
2.0 (including) |
2.0 (including) |
References