PT-2019-13024 · Mailenable · Mailenable Enterprise Premium

Published

2019-07-08

·

Updated

2020-08-24

·

CVE-2019-12924

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MailEnable Enterprise Premium version 10.23
Description The issue allows an unauthenticated user to exploit an XML External Entity Injection (XXE) vulnerability in the configuration of the XML processor. This could enable an attacker to read any file on the host system. Since all credentials are stored in a cleartext file, it is possible for an attacker to steal all users' credentials, including those of the highest privileged users.
Recommendations For MailEnable Enterprise Premium version 10.23, consider disabling the XML processor or restricting its configuration to prevent XXE attacks until a patch is available. Additionally, restrict access to sensitive files on the host system to minimize the risk of credential theft.

Fix

XXE

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12924

Affected Products

Mailenable Enterprise Premium