The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attachment was uploaded by the user or came from a HTTP POST, which could allow local users to steal sensitive information like a password file.
AV:L/AC:L/Au:N/C:P/I:P/A:N
This vulnerability has a 0.33% probability of being exploited in the next 30 days, ranking higher than 24% of all scored CVEs.