cve/2024/CVE-2024-50624.md

19 lines
875 B
Markdown
Raw Normal View History

2025-09-29 21:09:30 +02:00
### [CVE-2024-50624](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50624)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen)
### Description
ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.example.com or http://example.com/.well-known/autoconfig for retrieving the configuration. This is related to kmail-account-wizard.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/w4zu/Debian_security