The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.
| Software | From | Fixed in |
|---|---|---|
| opensuse / leap | 42.2 | 42.2.x |
| opensuse / leap | 42.1 | 42.1.x |
| postfixadmin_project / postfixadmin | - | 3.0.2 |