Openfind MAIL2000 Webmail Post-Auth Cross-Site Scripting
Vulnerability Description
The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any parameter. This vulnerability affects many mail system of governments, organizations, companies and universities.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-15072
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Tony Kuo (CHT Security), Vtim (CHT Security)
References
- https://www.openfind.com.tw/taiwan/resource.html
- https://gist.github.com/chtsecurity/b3396500d4686ad47fb26f64967ef24a
- https://gist.github.com/tonykuo76/5bf1ac369d953d5276afe0a2d04c2147
- https://www.chtsecurity.com/download/0837ce00c27c73dd3ba3a0d4a7df3a41aaea1ac1e9831a5d61bb64ed484a3598.txt
- https://tvn.twcert.org.tw/taiwanvn/TVN-201909002
- https://www.twcert.org.tw/en/cp-128-3086-ff35d-2.html
More from Openfind
View All →Affected Vendor
Openfind
View all reports →