CVE-2020-29547: Citadel Webcit
Medium severity, CVSS 5.9. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands into an encrypted user session. This can lead to credential disclosure.
Affected products
- Citadel Webcit: up to and including 926
Published 2023-05-29. Last modified 2026-06-17.