Showing 2 vulnerabilities on this page for totemomail

Signals CISA KEV Ransomware Nuclei
kiteworks vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Kiteworks Totemomail 7.x and 8.x before 8.3.0 allows /responsiveUI/EnvelopeOpenServlet messageId directory traversal for unauthenticated file read and delete operations (with displayLoginChunkedImages) and write operations (with storeLoginChunkedImages).

CWE-26May 18, 2024
CVSS9.8v3.1EPSS0.856%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.

CWE-79May 18, 2024
CVSS6.1v3.1EPSS0.269%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX