Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks and obtain certain configuration and version information.

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.