Description
SmarterTools SmarterMail contains an unauthenticated administrative password reset vulnerability. The application exposes an API endpoint that accepts password reset requests without verifying a secret. By sending a crafted POST request with a target username and desired password, a remote unauthenticated attacker can overwrite the administrator's credentials, gaining full control over the mail server administration interface.
Remediation
Upgrade SmarterMail to the latest patched version and ensure all security updates are applied regularly.
References
Related Vulnerabilities
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2026-28388)
Roundcube Improper Input Validation Vulnerability (CVE-2011-1492)
Joomla! Core Security Bypass (2.5.0 - 3.8.7)
Moodle Improper Input Validation Vulnerability (CVE-2013-2083)
Internet Information Services Other Vulnerability (CVE-1999-1478)