Description
Hosted services do not verify the sender of an email against authenticated users, allowing an attacker to spoof the identify of another user’s email address.
References
https://kb.cert.org/vuls/id/244112
https://www.kb.cert.org/vuls/id/244112