totemo records
9 published records for vendor totemo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-284 Improper Access Control1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-639 Authorization Bypass Through User-Controlled Key1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2018-6563Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers tototemo · encryption gateway · CWE-352 | High8.8 | — | 2.3% | Jun 20, 2018 |
30Monitor | CVE-2018-6562No exploit | totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user sessions and encryption keytotemo · totemomail encryption gateway · CWE-345 | High7.5 | — | 0.7% | May 18, 2018 |
24Monitor | CVE-2018-15511No exploit | Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to injtotemo · totemomail · CWE-79 | Medium6.1 | — | 1.0% | Aug 30, 2019 |
24Monitor | CVE-2018-15512No exploit | Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to injtotemo · totemomail · CWE-79 | Medium6.1 | — | 1.0% | Aug 30, 2019 |
24Monitor | CVE-2018-15510No exploit | Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrtotemo · totemomail · CWE-79 | Medium6.1 | — | 0.6% | Aug 30, 2019 |
24Monitor | CVE-2024-28063No exploit | Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.totemo · totemomail · CWE-79 | Medium6.1 | — | 0.3% | May 18, 2024 |
21Monitor | CVE-2018-15513No exploit | Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor rototemo · totemomail · CWE-284 | Medium5.3 | — | 1.0% | Aug 30, 2019 |
21Monitor | CVE-2019-17189No exploit | totemodata 3.0.0_b936 has XSS via a folder name.totemo · totemodata · CWE-79 | Medium5.4 | — | 0.8% | Oct 22, 2019 |
21Monitor | CVE-2020-7918No exploit | An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail foldertotemo · totemomail · CWE-639 | Medium5.4 | — | 0.7% | Mar 27, 2020 |
- CVE-2018-656336Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to
HighCVSS 8.8Proof of conceptEPSS 2%totemo · encryption gatewayJun 20, 2018
- CVE-2018-656230Monitor
totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user sessions and encryption key
HighCVSS 7.5No exploitEPSS 1%totemo · totemomail encryption gatewayMay 18, 2018
- CVE-2018-1551124Monitor
Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inj
MediumCVSS 6.1No exploitEPSS 1%totemo · totemomailAug 30, 2019
- CVE-2018-1551224Monitor
Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inj
MediumCVSS 6.1No exploitEPSS 1%totemo · totemomailAug 30, 2019
- CVE-2018-1551024Monitor
Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitr
MediumCVSS 6.1No exploitEPSS 1%totemo · totemomailAug 30, 2019
- CVE-2024-2806324Monitor
Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.
MediumCVSS 6.1No exploitEPSS 0%totemo · totemomailMay 18, 2024
- CVE-2018-1551321Monitor
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor ro
MediumCVSS 5.3No exploitEPSS 1%totemo · totemomailAug 30, 2019
- CVE-2019-1718921Monitor
totemodata 3.0.0_b936 has XSS via a folder name.
MediumCVSS 5.4No exploitEPSS 1%totemo · totemodataOct 22, 2019
- CVE-2020-791821Monitor
An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder
MediumCVSS 5.4No exploitEPSS 1%totemo · totemomailMar 27, 2020