Descrição
** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests (-HTTP Request/Response Smuggling-) vulnerability in Pony Mail leading to admin account takeover. This issue affects all versions of the Lua implementation of Pony Mail. There is a Python implementation under development under the name -Pony Mail Foal- that is not affected by this issue, but hasn-t been released yet. As the Lua implementation of this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS 9.8EPSS 0.44400000000000006%Risco 1.02
Ver fonte- Publicação
- 2026-04-28 16:16:13
- Versões afetadas
- unknown
- Tipo
- Outro
- Vetor
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H