Description
The addnew script in Argosoft Mail Server Pro 1.8.7.6 allows remote attackers to create arbitrary accounts, even if "Allow Creation of Accounts From the Web Interface" is disabled, via a direct HTTP POST request.
Affected products
- argosoft / argosoft_mail_server1.8.7.6 – 1.8.7.6