ZeroHour

CVE-2024-23824

PoC
CVSS 3.1
2.7 low
EPSS
<1%p47
Published
()
Modified
Description

mailcow is a dockerized email package, with multiple containers linked in one bridged network. The application is vulnerable to pixel flood attack, once the payload has been successfully uploaded in the logo the application goes slow and doesn't respond in the admin page. It is tested on the versions 2023-12a and prior and patched in version 2024-01.

Vendors
mailcow
Products
mailcow\
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.