CVE-2021-41083 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Dada Mail versions 11.15.1 and below. An attacker could craft a malicious webpage that, when visited by a logged-in Dada Mail user, allows the attacker to take control of the list control panel, including changing passwords and gaining complete control over mailing lists and profile logins. This vulnerability has a CVSS score of 8.8 (High), indicating a severe impact on confidentiality, integrity, and availability, with a network attack vector and low attack complexity, requiring user interaction. While confirmed through testing, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.16.0CPE matchmatch criteria | cpe:2.3:a:dadamailproject:dada_mail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.