Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variables and read or write the attachments and preferences of other users.
AV:N/AC:L/Au:N/C:P/I:P/A:N
This vulnerability has a 9.98% probability of being exploited in the next 30 days, ranking higher than 95% of all scored CVEs.