View Issue Details

IDProjectCategoryView StatusLast Update
0004626SOGoWeb Mailpublic2018-12-20 11:16
ReporterASolana Assigned To 
PrioritynormalSeveritymajorReproducibilityalways
Status newResolutionopen 
Platform[Server] LinuxOSUbuntuOS Version16.04 LTS
Product Version4.0.4 
Summary0004626: SOGo server accepts changed From address in send post action
Description

If SOGO POST send message action is intercepted and mail from address is changed SOGo let this message to be sent.

SOGo would have to detect that mail from address doesn't belong to logged user and then stop message sending.

Steps To Reproduce
    • UserA enters in SOGo webmail
    • UserA create new message in order to send to a private list "MailistX" created by UserB. Press the send button which creates a send POST request.
  1. This POST is intercepted with Burp, and the MAIL FROM is changed to UserB as shown in the attached screenshot (1.mailfrom_before.post.png).

  2. The mail is sent and all the members of the list receive the email without any problem.

I've attached screen captures (burp example and a sent message example after message being "changed").

TagsNo tags attached.

Activities

ASolana

ASolana

2018-12-20 11:16

reporter  

Issue History

Date Modified Username Field Change
2018-12-20 11:16 ASolana New Issue
2018-12-20 11:16 ASolana File Added: screen.capture.post.send.zip