Description
The Roundcube component of Analogic Poste.io 2.1.6 uses .htaccess to protect the logs/ folder, which is effective with the Apache HTTP Server but is ineffective with nginx. Attackers can read logs via the webmail/logs/sendmail URI.
References (2)
Core 2
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://bitbucket.org/analogic/mailserver/issues/665/posteio-logs-leak
Release Notes, Vendor Advisory x_refsource_misc
https://poste.io/changelog
Scores
CVSS v3
4.3
EPSS
0.0101
EPSS Percentile
58.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-693
Status
published
Products (1)
analogic/poste.io
2.1.6
Published
Jun 24, 2019
Tracked Since
Feb 18, 2026