U.N.U. Mailgust 1.9 allows remote attackers to obtain sensitive information via a direct request to index.php with method=showfullcsv, which reveals the POP3 server configuration, including account name and password.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mailgust | Unu_networks | 1.9 (including) | 1.9 (including) |