PT-2019-13971 · Mail2000 · Mail2000
Tony Kuo
·
Published
2019-11-20
·
Updated
2019-11-22
·
CVE-2019-15073
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MAIL2000 versions 6.0 and earlier
MAIL2000 version 7.0
Description
The issue is an Open Redirect vulnerability that affects all browsers, allowing redirection to a malicious site without authentication. This problem impacts numerous mail systems of governments, organizations, companies, and universities.
Recommendations
For MAIL2000 versions 6.0 and earlier, update to a version later than 6.0 to resolve the issue.
For MAIL2000 version 7.0, update to a version later than 7.0 to resolve the issue.
As a temporary workaround, consider restricting access to sensitive mail system functionalities to minimize the risk of exploitation.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mail2000