Unrated severityNVD Advisory· Published Dec 31, 2002· Updated Jun 16, 2026
CVE-2002-1648
CVE-2002-1648
Description
Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_to and subject parameters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:squirrelmail:squirrelmail:1.2.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:squirrelmail:squirrelmail:1.2.2:*:*:*:*:*:*:*
- (no CPE)range: <1.2.3
Patches
Vulnerability mechanics
References
4- www.securityfocus.com/bid/3956nvdPatch
- archives.neohapsis.com/archives/bugtraq/2002-01/0310.htmlnvdExploit
- www.kb.cert.org/vuls/id/153043nvdUS Government Resource
- exchange.xforce.ibmcloud.com/vulnerabilities/7989nvd
News mentions
0No linked articles in our index yet.