The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browsers previous login session in an error page, which allows local users to read another users inbox.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Imho_webmail | Imho | 0.96 (including) | 0.96 (including) |
Imho_webmail | Imho | 0.96.1 (including) | 0.96.1 (including) |
Imho_webmail | Imho | 0.96.2 (including) | 0.96.2 (including) |
Imho_webmail | Imho | 0.96.3 (including) | 0.96.3 (including) |
Imho_webmail | Imho | 0.97 (including) | 0.97 (including) |
Imho_webmail | Imho | 0.97.1 (including) | 0.97.1 (including) |
Imho_webmail | Imho | 0.98 (including) | 0.98 (including) |
Imho_webmail | Imho | 0.98.2 (including) | 0.98.2 (including) |
Imho_webmail | Imho | 0.98.3 (including) | 0.98.3 (including) |