SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mailing lists.
References
Link | Resource |
---|---|
https://www.smartertools.com/smartermail/release-notes/current | Exploit Release Notes Vendor Advisory |
https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabilities-in-smartermail/ | Third Party Advisory |
Configurations
Information
Published : 2019-04-24 08:29
Updated : 2020-02-10 13:53
NVD link : CVE-2019-7212
Mitre link : CVE-2019-7212
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
smartertools
- smartermail