CVE-2002-1648

Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_to and subject parameters.

Scoring

CVSS base score
0.05
EPSS probability
1.27%
Published
2005-03-28
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs