← Zurück zur CVE-Suche

CVE-2026-8142

VINCE

Beschreibung

VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.

CVSS 6.5EPSS 0.11499999999999999%Risiko 0.66
Quelle öffnen
Veröffentlicht
2026-05-07 20:16:45
Betroffene Versionen
<=3.0.38
Typ
Core software
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N