View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0004626 | SOGo | Web Mail | public | 2018-12-20 11:16 | 2018-12-20 11:16 |
Reporter | ASolana | Assigned To | |||
Priority | normal | Severity | major | Reproducibility | always |
Status | new | Resolution | open | ||
Platform | [Server] Linux | OS | Ubuntu | OS Version | 16.04 LTS |
Product Version | 4.0.4 | ||||
Summary | 0004626: SOGo server accepts changed From address in send post action | ||||
Description | If SOGO POST send message action is intercepted and mail from address is changed SOGo let this message to be sent. SOGo would have to detect that mail from address doesn't belong to logged user and then stop message sending. | ||||
Steps To Reproduce |
I've attached screen captures (burp example and a sent message example after message being "changed"). | ||||
Tags | No tags attached. | ||||