CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 2.1. See the original NVD description below for full technical details.
CVE
CVE-2014-5447
Severity
LOW
CVSS
2.1
EPSS
0.37%
Original NVD Description
Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.