CVE-2018-6562: Totemo Totemomail Encryption Gateway

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user sessions and encryption key material via a JSONP hijacking attack.

Affected products

  • Totemo Totemomail Encryption Gateway: before 6.0.0_b567 (fixed in 6.0.0_b567)

Published 2018-05-18. Last modified 2026-06-17.