CVE-2018-6563

HIGH

totemo encryption_gateway < 6.0.0 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-6563. PoCs published by Compass Security.

AI-analyzed exploit summary This is a working proof-of-concept for a CSRF vulnerability in totemomail Encryption Gateway. It demonstrates how an attacker can craft a malicious web page to execute unauthorized actions on behalf of a logged-in user by replaying a sequence of requests.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack the authentication of users for requests that (1) change user settings, (2) send emails, or (3) change contact information by leveraging lack of an anti-CSRF token.

Exploits (1)

exploitdb WORKING POC
by Compass Security · htmlwebappsasp
https://www.exploit-db.com/exploits/44631

This is a working proof-of-concept for a CSRF vulnerability in totemomail Encryption Gateway. It demonstrates how an attacker can craft a malicious web page to execute unauthorized actions on behalf of a logged-in user by replaying a sequence of requests.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: totemomail Encryption Gateway 6.0.0_Build_371
Auth required
Prerequisites: Victim must be logged into the totemomail webmail interface · Attacker must craft a malicious web page and trick the victim into visiting it
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/542015/100/0/threaded
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44631/

Scores

CVSS v3 8.8
EPSS 0.0010
EPSS Percentile 27.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
totemo/encryption_gateway < 6.0.0
Published Jun 20, 2018
Tracked Since Feb 18, 2026