A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663.
Conclusion & alert: CVE-2009-0030 is rated Moderate Risk (52.4/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.68%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.05% | 1.68% | +0.63% |
| 2 | 2025-03-30 | 1.81% | 1.05% | -0.77% |
| 3 | 2025-03-29 | — | 1.81% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 2.0 | MEDIUM |
|
8.0 | 6.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2009-0030 |
ubuntu
|
low | CVE-2009-0030 low priority: Ubuntu including 1 source packages (squirrelmail), 5 status rows across 5 suites (dapper, gutsy, hardy, intrepid, upstream): not-affected 4, needs-triage 1. | https://ubuntu.com/security/CVE-2009-0030 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| squirrelmail | squirrelmail | 1.4.8 | cpe:2.3:a:squirrelmail:squirrelmail:1.4.8:*:*:*:*:*:*:* |