CVE-2019-12927

MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was possible to hijack the session cookie by exploiting this vulnerability.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise_premium:*:*:*
cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise_premium:*:*:*
cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise_premium:*:*:*
cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise_premium:*:*:*
cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise_premium:*:*:*

Information

Published : 2019-07-08 15:15

Updated : 2019-07-23 10:51


NVD link : CVE-2019-12927

Mitre link : CVE-2019-12927


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

mailenable

  • mailenable