6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Description
VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.
Basic Information
ID
CVE-2026-8142
Source
certcc
Published
May 7, 2026 at 19:54
Modified
May 8, 2026 at 13:55
Affected Product
Vendor
CERT/CC
Product
VINCE
Affected Versions
CERT/CC VINCE 0