Skip to content
Noroxi

totemo records

9 published records for vendor totemo.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

9 records
  • CVE-2018-6563
    36Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to

    HighCVSS 8.8Proof of conceptEPSS 2%

    totemo · encryption gatewayJun 20, 2018

  • CVE-2018-6562
    30Monitor

    totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user sessions and encryption key

    HighCVSS 7.5No exploitEPSS 1%

    totemo · totemomail encryption gatewayMay 18, 2018

  • Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inj

    MediumCVSS 6.1No exploitEPSS 1%

    totemo · totemomailAug 30, 2019

  • Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inj

    MediumCVSS 6.1No exploitEPSS 1%

    totemo · totemomailAug 30, 2019

  • Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitr

    MediumCVSS 6.1No exploitEPSS 1%

    totemo · totemomailAug 30, 2019

  • Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.

    MediumCVSS 6.1No exploitEPSS 0%

    totemo · totemomailMay 18, 2024

  • Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor ro

    MediumCVSS 5.3No exploitEPSS 1%

    totemo · totemomailAug 30, 2019

  • totemodata 3.0.0_b936 has XSS via a folder name.

    MediumCVSS 5.4No exploitEPSS 1%

    totemo · totemodataOct 22, 2019

  • CVE-2020-7918
    21Monitor

    An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder

    MediumCVSS 5.4No exploitEPSS 1%

    totemo · totemomailMar 27, 2020