CVE-2017-5930: Opensuse Leap
Low severity, CVSS 2.7. EPSS: 15% chance of exploitation in the next 30 days.
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.
Affected products
- Opensuse Leap: version 42.1 only; version 42.2 only
- Postfixadmin Project Postfixadmin: before 3.0.2 (fixed in 3.0.2)
Published 2017-03-20. Last modified 2026-06-17.