What the vulnerability does
01Description
Missing Authorization vulnerability in Zoho Mail Zoho ZeptoMail allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zoho ZeptoMail: from n/a through 3.2.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in Zoho Mail Zoho ZeptoMail allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zoho ZeptoMail: from n/a through 3.2.9.
Explanation of Vulnerability in Simple Terms
ZeptoMail versions up to 3.2.9 lack proper authorization checks, allowing authenticated users to trigger a denial-of-service condition. An attacker with valid credentials can make requests that degrade service availability. The vulnerability requires login access and does not affect data confidentiality or integrity.
What an attacker can do
Degrade or disrupt ZeptoMail service availability by making authenticated requests.
Potential impact on your site
Legitimate users may experience service interruptions if an attacker with credentials exploits this flaw.
Conditions required to exploit
Attacker must have valid ZeptoMail login credentials.
Key dates
External resources
Related vulnerabilities