CVE-2015-3141
Last modified
CVE-2015-3141 is a vulnerability of currently unknown severity. Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies Xeams 4.5 Build 5755 and earlier allow remote attackers to hijack the authentication of administrators for requests that create an (1) SMTP domain or a (2) user via a request to /FrontController; or conduct cross-site scripting (XSS) attacks via the (3) domainname parameter to /FrontController, when creating a new SMTP domain configuration; the (4) txtRecipient parameter to /FrontController, when creating a new forwarder; the (5) popFetchServer, (6) popFetchUser, or (7) popFetchRecipient parameter to /FrontController, when creating a new POP3 Fetcher account; or the (8) Smtp HELO domain in the Advanced Server Configuration.. EPSS estimates a 2.00% chance of exploitation in the next 30 days.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies Xeams 4.5 Build 5755 and earlier allow remote attackers to hijack the authentication of administrators for requests that create an (1) SMTP domain or a (2) user via a request to /FrontController; or conduct cross-site scripting (XSS) attacks via the (3) domainname parameter to /FrontController, when creating a new SMTP domain configuration; the (4) txtRecipient parameter to /FrontController, when creating a new forwarder; the (5) popFetchServer, (6) popFetchUser, or (7) popFetchRecipient parameter to /FrontController, when creating a new POP3 Fetcher account; or the (8) Smtp HELO domain in the Advanced Server Configuration.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Synametrics | Xeams | <= 4.5 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-3141?
How severe is CVE-2015-3141?
How do I fix CVE-2015-3141?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-3134Adobe Flash Player before 13.0.0.302 and 14.x through 18.x b…
- CVE-2015-3135Heap-based buffer overflow in Adobe Flash Player before 13.0…
- CVE-2015-3136Use-after-free vulnerability in Adobe Flash Player before 13…
- CVE-2015-3137Use-after-free vulnerability in Adobe Flash Player before 13…
- CVE-2015-3138print-wb.c in tcpdump before 4.7.4 allows remote attackers t…
- CVE-2015-3140Multiple cross-site request forgery (CSRF) vulnerabilities i…8.8
- CVE-2015-3142The kernel-invoked coredump processor in Automatic Bug Repor…
- CVE-2015-3143cURL and libcurl 7.10.6 through 7.41.0 does not properly re-…
- CVE-2015-3144The fix_hostname function in cURL and libcurl 7.37.0 through…
- CVE-2015-3145The sanitize_cookie_path function in cURL and libcurl 7.31.0…
- CVE-2015-3146The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet h…
- CVE-2015-3147daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool…6.5
Are you affected by CVE-2015-3141?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
