CVE-2019-15071
Last modified
CVE-2019-15071 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. EPSS estimates a 1.63% chance of exploitation in the next 30 days.
Description
The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail system of governments, organizations, companies and universities.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openfind | Mail2000 | >= 6.0, <= 7.0 |
References
- https://gist.github.com/chtsecurity/21119b393640bea1d010ab9e3bee216dThird Party Advisory
- https://gist.github.com/tonykuo76/95638395e0c83e68dbd3db0fa0184e27Third Party Advisory
- https://tvn.twcert.org.tw/taiwanvn/TVN-201909001Third Party Advisory
- https://www.openfind.com.tw/taiwan/resource.htmlProduct, Vendor Advisory
- https://www.twcert.org.tw/en/cp-128-3085-45bda-2.htmlThird Party Advisory
- https://gist.github.com/chtsecurity/21119b393640bea1d010ab9e3bee216dThird Party Advisory
- https://gist.github.com/tonykuo76/95638395e0c83e68dbd3db0fa0184e27Third Party Advisory
- https://tvn.twcert.org.tw/taiwanvn/TVN-201909001Third Party Advisory
- https://www.openfind.com.tw/taiwan/resource.htmlProduct, Vendor Advisory
- https://www.twcert.org.tw/en/cp-128-3085-45bda-2.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-15071?
How severe is CVE-2019-15071?
How do I fix CVE-2019-15071?
Are you affected by CVE-2019-15071?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
