VYPR
Medium severity6.5NVD Advisory· Published Mar 15, 2018· Updated Jun 17, 2026

CVE-2018-7701

CVE-2018-7701

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) delete e-mail messages via a delete action in a request to secmail/getmessage.exe or (2) spoof arbitrary users and reply to their messages via a request to secserver/securectrl.exe.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:securenvoy:securmail:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:securenvoy:securmail:*:*:*:*:*:*:*:*range: <9.2.501
    • (no CPE)range: <9.2.501

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.