Brightmail Spamfilter 6.0 and earlier beta releases allows remote attackers to read mail from other users by modifying the id parameter in a viewMsgDetails.do request.
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16609
No PoCs found on GitHub currently.