CVE-2019-12970
Last modified
CVE-2019-12970 is a vulnerability of currently unknown severity. XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. EPSS estimates a 1.82% chance of exploitation in the next 30 days.
Description
XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context via crafted use of (for example) a NOEMBED, NOFRAMES, NOSCRIPT, or TEXTAREA element.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Squirrelmail | Squirrelmail | <= 1.4.22 |
| Squirrelmail | Squirrelmail | >= 1.5.0, <= 1.5.2 |
References
- http://packetstormsecurity.com/files/153495/SquirrelMail-1.4.22-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://seclists.org/bugtraq/2019/Jul/0Exploit, Mailing List, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-016.txtExploit, Third Party Advisory
- http://packetstormsecurity.com/files/153495/SquirrelMail-1.4.22-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://seclists.org/bugtraq/2019/Jul/0Exploit, Mailing List, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-016.txtExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-12970?
How severe is CVE-2019-12970?
How do I fix CVE-2019-12970?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-12963LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the …
- CVE-2019-12964LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the …
- CVE-2019-12966FeHelper through 2019-06-19 allows arbitrary code execution …
- CVE-2019-12967Stephan Mooltipass Moolticute through 0.42.1 (and possibly e…6.5
- CVE-2019-12968A vulnerability was found in the Sonic Robo Blast 2 (SRB2) p…
- CVE-2019-1297A remote code execution vulnerability exists in Microsoft Ex…8.8
- CVE-2019-12971BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestric…
- CVE-2019-12972An issue was discovered in the Binary File Descriptor (BFD) …5.5
- CVE-2019-12973In OpenJPEG 2.3.1, there is excessive iteration in the opj_t…5.5
- CVE-2019-12974A NULL pointer dereference in the function ReadPANGOImage in…
- CVE-2019-12975ImageMagick 7.0.8-34 has a memory leak vulnerability in the …5.5
- CVE-2019-12976ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage f…5.5
Are you affected by CVE-2019-12970?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
