VYPR

totomail Encryption Gateway

by Totemo

CVEs (2)

  • CVE-2018-6563HigJun 20, 2018
    risk 0.60cvss 8.8epss 0.02

    Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack the authentication of users for requests that (1) change user settings, (2) send emails, or (3) change contact information by…

  • CVE-2018-6562HigMay 18, 2018
    risk 0.49cvss 7.5epss 0.01

    totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user sessions and encryption key material via a JSONP hijacking attack.