CVE-2025-0431
CVE-2025-0431
Título es
CVE-2025-0431
Mié, 19/03/2025 – 17:15
Tipo
CWE-790
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-0431
Descripción en
Enterprise Protection contains a vulnerability in URL rewriting that allows an unauthenticated remote attacker to send an email which bypasses URL protections impacting the integrity of recipient's email. This occurs due to improper filtering of backslashes within URLs and affects all versions of 8.21, 8.20 and 8.18 prior to 8.21.0 patch 5115, 8.20.6 patch 5114 and 8.18.6 patch 5113 respectively.
19/03/2025
19/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
5.80
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2025-0001
Enviar en el boletín
Off
