CVE-2017-5930

LOW EXPLOITED

Opensuse Leap < 3.0.2 - Missing Authorization

Title source: rule
STIX 2.1

Exploitation Summary

CVE-2017-5930 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Jan-Frederik Rieckers, including a Metasploit module auxiliary/admin/http/pfadmin_set_protected_alias.

AI-analyzed exploit summary This Metasploit module exploits a vulnerability in Postfixadmin (CVE-2017-5930) where protected aliases can be deleted and recreated to redirect emails. It authenticates as an admin, deletes the target alias, and recreates it with a new destination.

Description

The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.

Exploits (1)

metasploit WORKING POC
by Jan-Frederik Rieckers · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/pfadmin_set_protected_alias.rb

This Metasploit module exploits a vulnerability in Postfixadmin (CVE-2017-5930) where protected aliases can be deleted and recreated to redirect emails. It authenticates as an admin, deletes the target alias, and recreates it with a new destination.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Postfixadmin 2.91 to 3.0.1
Auth required
Prerequisites: Valid admin credentials · Target alias name · New redirection email address
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Patch, Third Party Advisory mailing-list x_refsource_mlist
https://sourceforge.net/p/postfixadmin/mailman/message/35646827/
Third Party Advisory, VDB Entry, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96142
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2017-02/msg00076.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2017/02/08/1
Patch, Third Party Advisory x_refsource_confirm
https://github.com/postfixadmin/postfixadmin/pull/23
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2017/02/09/1

Scores

CVSS v3 2.7
EPSS 0.5870
EPSS Percentile 98.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

Details

VulnCheck KEV 2022-01-26
CWE
CWE-862
Status published
Products (3)
opensuse/leap 42.1
opensuse/leap 42.2
postfixadmin_project/postfixadmin < 3.0.2
Published Mar 20, 2017
Tracked Since Feb 18, 2026