CVE-2026-90936

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
4.3
MEDIUM

Description

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying arbitrary senderid parameters in delete confirmation requests.

Published
September 14, 2026 1:19 PM
Last Modified
September 14, 2026 1:19 PM
Source
[email protected]

Weaknesses (CWE)

CWE-200

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.