Axigen Mail Server
cpe:2.3:a:axigen:axigen_mail_server:*:*:*:*:*:*:*
- ~10.3
- ~10.4
- ~10.5
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Axigen Mail Server WebAdmin interface, affecting versions prior to 10.5.57 and 10.6.x prior to 10.6.26. The vulnerability arises from improper handling of the '_s' (breadcrumb) parameter, allowing attackers to craft malicious URLs that execute arbitrary administrative actions when clicked by administrators. This exploitation occurs without additional user interaction, potentially leading to the creation of unauthorized administrator accounts or modifications to critical server configurations.
Exploitation of this vulnerability allows for Cross-Site Request Forgery, enabling attackers to perform actions on behalf of an authenticated administrator, such as creating unauthorized admin accounts or altering essential server settings.
Users can update to Axigen versions 10.5.57 or 10.6.26 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.