CVE-2017-5930

low
Published 2017-03-20 · Modified 2026-05-13
CVSS v3
2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
CVSS v2
3.5
VIR risk
2.7

Description

The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.

Predictions

Exploit likelihood
39%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2017-5930

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://sourceforge.net/p/postfixadmin/mailman/message/35646827/

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/postfixadmin/postfixadmin/pull/23

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/postfixadmin/postfixadmin/blob/postfixadmin-3.0.2/CHANGELOG.TXT

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.securityfocus.com/bid/96142

OS impact

OSVersionStatusFixed in
suse suse42.1affected
suse suse42.2affected
debian debianbookwormfixed3.0.2-1
debian debianforkyfixed3.0.2-1
debian debiansidfixed3.0.2-1
debian debiantrixiefixed3.0.2-1

Application impact

VendorProductVersionsFixed
postfixadmin_projectpostfixadmin{"endExcluding":"3.0.2"}3.0.2

References

CWEs

CWE-862

Verify integrity in audit chain (admin only). AS-IS.