It has been reported that Gordano Messaging Suite may be prone to an information disclosure vulnerability allowing users to access sensitive information without being authenticated as administrators. This issue is reported to present itself in the Alertlist.mml module of the software. Successful exploitation of this issue may allow an attacker to access sensitive data such as usernames, domains, and logged in times, which may be used to launch further attacks.
It has been reported that Gordano Messaging Suite may be prone to an information disclosure vulnerability allowing users to access sensitive information without being authenticated as administrators. This issue is reported to present itself in the Alertlist.mml module of the software. Successful exploitation of this issue may allow an attacker to access sensitive data such as usernames, domains, and logged in times, which may be used to launch further attacks.