CVE-2022-39258
mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Authorize links. This could redirect a victim to an attacker controller place to steal Swagger authorization credentials or create a phishing page to steal other information. The issue has been fixed with the 2022-09 mailcow Mootember Update. As a workaround, one may delete the Swapper API Documentation from their e-mail server.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- EPSS probability
- 0.26%
- CWE
- CWE-451, CWE-200
- Published
- 2022-09-27
- Last modified
- 2026-03-13
Affected products
- mailcow mailcow-dockerized
Weakness type
Related vulnerabilities
- CVE-2026-79011 — UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engi
- CVE-2020-9236 — There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does no
- CVE-2024-52277 — PDF Document Spoofing in DocuSeal
- CVE-2024-52276 — PDF Document Spoofing in DocuSign
- CVE-2024-52271 — PDF Document Spoofing in Documenso
- CVE-2024-52270 — PDF Document Spoofing in DropBox Sign(HelloSign)
- CVE-2024-52269 — AI Assistant PDF Document Spoofing in DocuSign
- CVE-2026-79108 — UI misrepresentation in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a