Vulnerabilities
Vulnerable Software
Mailenable:  >> Mailenable  >> 10.14  Security Vulnerabilities
Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could lead an attacker to store arbitrary code on that files and execute RCE commands.
CVSS Score
8.8
EPSS Score
0.002
Published
2023-01-13
MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was possible to hijack the session cookie by exploiting this vulnerability.
CVSS Score
6.1
EPSS Score
0.001
Published
2019-07-08


Contact Us

Shodan ® - All rights reserved