CyberRota Analysis
AI-GeneratedThe SEPPmail Secure Email Gateway and SEPPmail Cloud prior to version 15.0.4.2 are vulnerable to session hijacking due to the exposure of session tokens in both the URL and HTTP headers, allowing attackers to replay and take control of user sessions in the GINA web portal. Organizations using these products should prioritize patching to mitigate the risk of unauthorized access to sensitive email communications. This vulnerability is particularly critical for businesses relying on secure email solutions for their operations.
Original NVD Description
SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.