← Back

CVE-2023-4595

nvd nist
Published: Nov 23, 2023Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of the following parameters to the end of the URL: %00 %0a, %20, %2a, %a0, %aa, %c0 and %ca.

Affected (1)

Products: Seattlelab: Slmail
1 product
Slmail
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 5.5.0.4433
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (2)

Timeline

No history available yet.