An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a non-existent email address is provided as part of the email parameter, SpamTitan will automatically create a user record and associate quarantine settings with it - all without requiring authentication.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 09 Oct 2025 12:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Thu, 21 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-284 CWE-306 | |
| Metrics | cvssV3_1 
 
 | 
Thu, 21 Aug 2025 16:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a non-existent email address is provided as part of the email parameter, SpamTitan will automatically create a user record and associate quarantine settings with it - all without requiring authentication. | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2025-08-21T00:00:00.000Z
Updated: 2025-10-09T12:21:39.895Z
Reserved: 2024-08-29T00:00:00.000Z
Link: CVE-2024-45438
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-08-21T17:54:28.203Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-08-21T17:15:29.553
Modified: 2025-10-09T13:15:30.703
Link: CVE-2024-45438
 Redhat
                        Redhat
                    No data.