PT-2019-13025 · Mailenable · Mailenable Enterprise Premium

Publicado

2019-07-08

·

Atualizado

2019-07-16

·

CVE-2019-12925

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions MailEnable Enterprise Premium version 10.23
Description The issue allows authenticated users to perform directory traversal, enabling them to add, remove, or potentially read files in arbitrary folders accessible by the IIS user. This could lead to unauthorized access to other users' credentials, including those of SYSADMIN accounts, as well as reading other users' emails or adding emails or files to other users' accounts.
Recommendations For MailEnable Enterprise Premium version 10.23, update to a newer version that addresses the directory traversal issues to prevent unauthorized access and potential data breaches.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-12925

Produtos afetados

Mailenable Enterprise Premium