Vulnerability Details CVE-2019-12927
MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was possible to hijack the session cookie by exploiting this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.0%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2019-12927
-
cpe:2.3:a:mailenable:mailenable:10.00
-
cpe:2.3:a:mailenable:mailenable:10.10
-
cpe:2.3:a:mailenable:mailenable:10.11
-
cpe:2.3:a:mailenable:mailenable:10.12
-
cpe:2.3:a:mailenable:mailenable:10.13
-
cpe:2.3:a:mailenable:mailenable:10.14
-
cpe:2.3:a:mailenable:mailenable:10.15
-
cpe:2.3:a:mailenable:mailenable:10.16
-
cpe:2.3:a:mailenable:mailenable:10.17
-
cpe:2.3:a:mailenable:mailenable:10.18
-
cpe:2.3:a:mailenable:mailenable:10.19
-
cpe:2.3:a:mailenable:mailenable:10.20
-
cpe:2.3:a:mailenable:mailenable:10.21
-
cpe:2.3:a:mailenable:mailenable:10.22
-
cpe:2.3:a:mailenable:mailenable:10.23
-
cpe:2.3:a:mailenable:mailenable:6.0
-
cpe:2.3:a:mailenable:mailenable:6.01
-
cpe:2.3:a:mailenable:mailenable:6.02
-
cpe:2.3:a:mailenable:mailenable:6.03
-
cpe:2.3:a:mailenable:mailenable:6.5
-
cpe:2.3:a:mailenable:mailenable:6.51
-
cpe:2.3:a:mailenable:mailenable:6.52
-
cpe:2.3:a:mailenable:mailenable:6.53
-
cpe:2.3:a:mailenable:mailenable:6.54
-
cpe:2.3:a:mailenable:mailenable:6.55
-
cpe:2.3:a:mailenable:mailenable:6.56
-
cpe:2.3:a:mailenable:mailenable:6.57
-
cpe:2.3:a:mailenable:mailenable:6.58
-
cpe:2.3:a:mailenable:mailenable:6.59
-
cpe:2.3:a:mailenable:mailenable:6.60
-
cpe:2.3:a:mailenable:mailenable:6.61
-
cpe:2.3:a:mailenable:mailenable:6.62
-
cpe:2.3:a:mailenable:mailenable:6.63
-
cpe:2.3:a:mailenable:mailenable:6.64
-
cpe:2.3:a:mailenable:mailenable:6.65
-
cpe:2.3:a:mailenable:mailenable:6.70
-
cpe:2.3:a:mailenable:mailenable:6.71
-
cpe:2.3:a:mailenable:mailenable:6.72
-
cpe:2.3:a:mailenable:mailenable:6.73
-
cpe:2.3:a:mailenable:mailenable:6.74
-
cpe:2.3:a:mailenable:mailenable:6.75
-
cpe:2.3:a:mailenable:mailenable:6.76
-
cpe:2.3:a:mailenable:mailenable:6.77
-
cpe:2.3:a:mailenable:mailenable:6.78
-
cpe:2.3:a:mailenable:mailenable:6.79
-
cpe:2.3:a:mailenable:mailenable:6.80
-
cpe:2.3:a:mailenable:mailenable:6.81
-
cpe:2.3:a:mailenable:mailenable:6.82
-
cpe:2.3:a:mailenable:mailenable:6.83
-
cpe:2.3:a:mailenable:mailenable:6.84
-
cpe:2.3:a:mailenable:mailenable:6.85
-
cpe:2.3:a:mailenable:mailenable:6.86
-
cpe:2.3:a:mailenable:mailenable:6.87
-
cpe:2.3:a:mailenable:mailenable:6.88
-
cpe:2.3:a:mailenable:mailenable:6.89
-
cpe:2.3:a:mailenable:mailenable:7.0
-
cpe:2.3:a:mailenable:mailenable:7.01
-
cpe:2.3:a:mailenable:mailenable:7.02
-
cpe:2.3:a:mailenable:mailenable:7.03
-
cpe:2.3:a:mailenable:mailenable:7.04
-
cpe:2.3:a:mailenable:mailenable:7.05
-
cpe:2.3:a:mailenable:mailenable:7.06
-
cpe:2.3:a:mailenable:mailenable:7.07
-
cpe:2.3:a:mailenable:mailenable:7.08
-
cpe:2.3:a:mailenable:mailenable:7.09
-
cpe:2.3:a:mailenable:mailenable:7.50
-
cpe:2.3:a:mailenable:mailenable:7.51
-
cpe:2.3:a:mailenable:mailenable:7.52
-
cpe:2.3:a:mailenable:mailenable:7.53
-
cpe:2.3:a:mailenable:mailenable:7.54
-
cpe:2.3:a:mailenable:mailenable:7.55
-
cpe:2.3:a:mailenable:mailenable:7.56
-
cpe:2.3:a:mailenable:mailenable:7.57
-
cpe:2.3:a:mailenable:mailenable:7.58
-
cpe:2.3:a:mailenable:mailenable:7.59
-
cpe:2.3:a:mailenable:mailenable:7.60
-
cpe:2.3:a:mailenable:mailenable:7.61
-
cpe:2.3:a:mailenable:mailenable:8.00
-
cpe:2.3:a:mailenable:mailenable:8.01
-
cpe:2.3:a:mailenable:mailenable:8.02
-
cpe:2.3:a:mailenable:mailenable:8.03
-
cpe:2.3:a:mailenable:mailenable:8.04
-
cpe:2.3:a:mailenable:mailenable:8.50
-
cpe:2.3:a:mailenable:mailenable:8.51
-
cpe:2.3:a:mailenable:mailenable:8.52
-
cpe:2.3:a:mailenable:mailenable:8.53
-
cpe:2.3:a:mailenable:mailenable:8.54
-
cpe:2.3:a:mailenable:mailenable:8.55
-
cpe:2.3:a:mailenable:mailenable:8.56
-
cpe:2.3:a:mailenable:mailenable:8.57
-
cpe:2.3:a:mailenable:mailenable:8.58
-
cpe:2.3:a:mailenable:mailenable:8.59
-
cpe:2.3:a:mailenable:mailenable:8.60
-
cpe:2.3:a:mailenable:mailenable:8.61
-
cpe:2.3:a:mailenable:mailenable:8.62
-
cpe:2.3:a:mailenable:mailenable:8.63
-
cpe:2.3:a:mailenable:mailenable:9.0
-
cpe:2.3:a:mailenable:mailenable:9.01
-
cpe:2.3:a:mailenable:mailenable:9.02
-
cpe:2.3:a:mailenable:mailenable:9.03
-
cpe:2.3:a:mailenable:mailenable:9.04
-
cpe:2.3:a:mailenable:mailenable:9.05
-
cpe:2.3:a:mailenable:mailenable:9.10
-
cpe:2.3:a:mailenable:mailenable:9.11
-
cpe:2.3:a:mailenable:mailenable:9.12
-
cpe:2.3:a:mailenable:mailenable:9.13
-
cpe:2.3:a:mailenable:mailenable:9.14
-
cpe:2.3:a:mailenable:mailenable:9.15
-
cpe:2.3:a:mailenable:mailenable:9.16
-
cpe:2.3:a:mailenable:mailenable:9.17
-
cpe:2.3:a:mailenable:mailenable:9.18
-
cpe:2.3:a:mailenable:mailenable:9.50
-
cpe:2.3:a:mailenable:mailenable:9.51
-
cpe:2.3:a:mailenable:mailenable:9.52
-
cpe:2.3:a:mailenable:mailenable:9.53
-
cpe:2.3:a:mailenable:mailenable:9.54
-
cpe:2.3:a:mailenable:mailenable:9.60
-
cpe:2.3:a:mailenable:mailenable:9.61
-
cpe:2.3:a:mailenable:mailenable:9.62
-
cpe:2.3:a:mailenable:mailenable:9.70
-
cpe:2.3:a:mailenable:mailenable:9.71
-
cpe:2.3:a:mailenable:mailenable:9.72
-
cpe:2.3:a:mailenable:mailenable:9.73
-
cpe:2.3:a:mailenable:mailenable:9.74
-
cpe:2.3:a:mailenable:mailenable:9.75
-
cpe:2.3:a:mailenable:mailenable:9.76
-
cpe:2.3:a:mailenable:mailenable:9.77
-
cpe:2.3:a:mailenable:mailenable:9.78
-
cpe:2.3:a:mailenable:mailenable:9.79
-
cpe:2.3:a:mailenable:mailenable:9.80
-
cpe:2.3:a:mailenable:mailenable:9.81
-
cpe:2.3:a:mailenable:mailenable:9.82