CVE Feed

    Dashboard / CVE / CVE-2018-15667

    CVE-2018-15667

    An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. It registers and uses the airmail:// URL scheme. The "send" command in the URL scheme allows an external application to send arbitrary emails from an active account without authentication. The handler has no restriction on who can use its functionality. The handler can be invoked using any method that invokes the URL handler such as a hyperlink in an email. The user is not prompted when the handler processes the "send" command, thus leading to automatic transmission of an attacker crafted email from the target account.

    Published:Aug 21, 2018
    Last Modified:Nov 21, 2024
    EPS:Aug 21, 2018
    EPSS Score:0.00232
    CVSS Score:7.5

    Affected Products

    Vendor
    Airmailapp
    Product
    Airmail

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High