Back
CVE-2002-1648
Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_to and subject parameters.
Published: Dec 31, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| squirrelmail | squirrelmail | 1.2.2 |
GitHub Security Advisory GHSA-777c-m2xj-3qhf
Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3...
References (8)
- http://archives.neohapsis.com/archives/bugtraq/2002-01/0310.html Exploit
- http://www.kb.cert.org/vuls/id/153043 US Government Resource
- http://www.securityfocus.com/bid/3956 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7989
- http://archives.neohapsis.com/archives/bugtraq/2002-01/0310.html Exploit
- http://www.kb.cert.org/vuls/id/153043 US Government Resource
- http://www.securityfocus.com/bid/3956 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7989
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
3.44%
Top 12% most likely to be exploited
Threat Score
31 / 100
Data Sources
NVD
EPSS
GitHub