299,751
Total vulnerabilities in the database
The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attachment was uploaded by the user or came from a HTTP POST, which could allow local users to steal sensitive information like a password file.
| Software | From | Fixed in |
|---|---|---|
| basilix / basilix_webmail | 1.1.0 | 1.1.0.x |