Skip to main content

Vendor archive

totemo CVEs

Beta · best-effort

9 CVEs tagged to vendor totemo0 Critical, 2 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2024-28063

Published May 18, 2024

Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7918

Published Mar 27, 2020

An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15513

Published Aug 30, 2019

Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15512

Published Aug 30, 2019

Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15511

Published Aug 30, 2019

Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15510

Published Aug 30, 2019

Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6563

Published Jun 20, 2018

Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack the authentication of users for…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6562

Published May 18, 2018

totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user sessions and encryption key material via a JSONP hijacking attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1