Vulnerabilities
Vulnerable Software
Mailenable:  >> Mailenable  >> 8.03  Security Vulnerabilities
Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could lead an attacker to store arbitrary code on that files and execute RCE commands.
CVSS Score
8.8
EPSS Score
0.009
Published
2023-01-13
MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was possible to hijack the session cookie by exploiting this vulnerability.
CVSS Score
6.1
EPSS Score
0.009
Published
2019-07-08
MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled.
CVSS Score
9.1
EPSS Score
0.022
Published
2019-01-16
MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB after a password-change request.
CVSS Score
9.8
EPSS Score
0.025
Published
2019-01-16
MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.
CVSS Score
6.1
EPSS Score
0.013
Published
2019-01-16
MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.
CVSS Score
10.0
EPSS Score
0.018
Published
2019-01-16


Contact Us

Shodan ® - All rights reserved