Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Pegasus_mail |
David_harris |
3.12 (including) |
3.12 (including) |
References