Loading
Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.
Use CWE-20, Cyrusimap vendor hub and Cyrus Imap product page to widen CVE-2017-12843 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-34055 for nearby disclosures in the same product family.