CVE-2019-15071
Last modified
CVE-2019-15071 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. EPSS estimates a 1.63% chance of exploitation in the next 30 days.
Description
The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail system of governments, organizations, companies and universities.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openfind | Mail2000 | >= 6.0, <= 7.0 |
References
- https://gist.github.com/chtsecurity/21119b393640bea1d010ab9e3bee216dThird Party Advisory
- https://gist.github.com/tonykuo76/95638395e0c83e68dbd3db0fa0184e27Third Party Advisory
- https://tvn.twcert.org.tw/taiwanvn/TVN-201909001Third Party Advisory
- https://www.openfind.com.tw/taiwan/resource.htmlProduct, Vendor Advisory
- https://www.twcert.org.tw/en/cp-128-3085-45bda-2.htmlThird Party Advisory
- https://gist.github.com/chtsecurity/21119b393640bea1d010ab9e3bee216dThird Party Advisory
- https://gist.github.com/tonykuo76/95638395e0c83e68dbd3db0fa0184e27Third Party Advisory
- https://tvn.twcert.org.tw/taiwanvn/TVN-201909001Third Party Advisory
- https://www.openfind.com.tw/taiwan/resource.htmlProduct, Vendor Advisory
- https://www.twcert.org.tw/en/cp-128-3085-45bda-2.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-15071?
How severe is CVE-2019-15071?
How do I fix CVE-2019-15071?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-15065A service which is hosted on port 6998 in HiNet GPON firmwar…7.5
- CVE-2019-15066An “invalid command” handler issue was discovered in HiNet G…9.8
- CVE-2019-15067An authentication bypass vulnerability discovered in Smart B…9.8
- CVE-2019-15068A broken access control vulnerability in Smart Battery A4, a…9.8
- CVE-2019-15069An unsafe authentication interface was discovered in Smart B…9.8
- CVE-2019-1507Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-15072The login feature in "/cgi-bin/portal" in MAIL2000 through v…6.1
- CVE-2019-15073An Open Redirect vulnerability for all browsers in MAIL2000 …6.1
- CVE-2019-15074The Timeline feature in my_view_page.php in MantisBT through…
- CVE-2019-15075An issue was discovered in iNextrix ASTPP before 4.0.1. web_…7.5
- CVE-2019-15078An issue was discovered in a smart contract implementation f…7.5
- CVE-2019-15079A typo exists in the constructor of a smart contract impleme…7.5
Are you affected by CVE-2019-15071?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
