CVE-2019-12924

MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerability in the configuration of the XML processor to read any file on the host system. Because all credentials were stored in a cleartext file, it was possible to steal all users' credentials (including the highest privileged users).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
VendorProductVersion
mailenablemailenable
6.0 ≤
𝑥
< 6.90
mailenablemailenable
7.0 ≤
𝑥
< 7.62
mailenablemailenable
8.00 ≤
𝑥
< 8.64
mailenablemailenable
9.0 ≤
𝑥
< 9.83
mailenablemailenable
10.00 ≤
𝑥
< 10.24
𝑥
= Vulnerable software versions