CVE-2018-7705 describes a directory traversal vulnerability in SecurEnvoy SecurMail versions prior to 9.2.501. This flaw allows remote authenticated users to read email messages intended for arbitrary recipients by manipulating the filename parameter in a request to secupload2/upload.aspx. The vulnerability carries a high CVSS score of 8.1, indicating a significant risk. It requires authentication but has low attack complexity, allowing for high impact in terms of confidentiality and integrity. While there is no evidence of active exploitation (KEV list), public exploit code exists on ExploitDB, and the vulnerability has received some community discussion and media coverage, suggesting awareness among threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.2.501CPE matchmatch criteria | cpe:2.3:a:securenvoy:securmail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.