CVE-2020-29547

An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands into an encrypted user session. This can lead to credential disclosure.
Configurations

Configuration 1 (hide)

cpe:2.3:a:citadel:webcit:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-05-29 19:15

Updated : 2023-06-05 16:37


NVD link : CVE-2020-29547

Mitre link : CVE-2020-29547

CVE.ORG link : CVE-2020-29547


JSON object : View

Products Affected

citadel

  • webcit
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')