VendorsTotemototemomailall versions
Vulnerabilities

Totemo Totemomail

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2018-15511
Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
Published 2019-08-29 · Modified
6.1EPSS 0.010
CVE-2018-15512
Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
Published 2019-08-29 · Modified
6.1EPSS 0.010
CVE-2018-15510
Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
Published 2019-08-29 · Modified
6.1EPSS 0.006
CVE-2024-28063
Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.
Published 2024-05-18 · Analyzed
6.1EPSS 0.003
CVE-2020-7918
An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.
Published 2020-03-27 · Modified
5.5EPSS 0.007
CVE-2018-15513
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.
Published 2019-08-29 · Modified
5.3EPSS 0.010