PT-2019-13971 · Mail2000 · Mail2000
Tony Kuo
·
Publicado
2019-11-20
·
Atualizado
2019-11-22
·
CVE-2019-15073
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MAIL2000 versions 6.0 and earlier
MAIL2000 version 7.0
Description
The issue is an Open Redirect vulnerability that affects all browsers, allowing redirection to a malicious site without authentication. This problem impacts numerous mail systems of governments, organizations, companies, and universities.
Recommendations
For MAIL2000 versions 6.0 and earlier, update to a version later than 6.0 to resolve the issue.
For MAIL2000 version 7.0, update to a version later than 7.0 to resolve the issue.
As a temporary workaround, consider restricting access to sensitive mail system functionalities to minimize the risk of exploitation.
Correção
Open Redirect
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mail2000