PT-2019-13024 · Mailenable · Mailenable Enterprise Premium

Publicado

2019-07-08

·

Atualizado

2020-08-24

·

CVE-2019-12924

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MailEnable Enterprise Premium version 10.23
Description The issue allows an unauthenticated user to exploit an XML External Entity Injection (XXE) vulnerability in the configuration of the XML processor. This could enable an attacker to read any file on the host system. Since all credentials are stored in a cleartext file, it is possible for an attacker to steal all users' credentials, including those of the highest privileged users.
Recommendations For MailEnable Enterprise Premium version 10.23, consider disabling the XML processor or restricting its configuration to prevent XXE attacks until a patch is available. Additionally, restrict access to sensitive files on the host system to minimize the risk of credential theft.

Correção

XXE

Missing Encryption of Sensitive Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-12924

Produtos afetados

Mailenable Enterprise Premium