GHSA-gh4w-5vrf-hhcgHigh

SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal...

Published
May 8, 2026
Last Modified
May 18, 2026

🔗 CVE IDs covered (1)

📋 Description

SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows remote attackers to read arbitrary local files and trigger deletion of files in the targeted directory with the privileges of the api.app process.

🔗 References (4)