Openfind MAIL2000 Webmail Pre-Auth Open Redirect
Vulnerability Description
An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects many mail system of governments, organizations, companies and universities.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-15073
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Tony Kuo (CHT Security), Vtim (CHT Security)
References
- https://www.openfind.com.tw/taiwan/resource.html
- https://gist.github.com/chtsecurity/512ebad24dddffb5321cf5f1a336f90f
- https://gist.github.com/tonykuo76/ed1cc21cf755bfb8b67ca24f50bded13
- https://www.chtsecurity.com/download/258686130f7a16063c765f9e79cffd813409f6fe61c2dec05fceca541762d5bd.txt
- https://www.twcert.org.tw/en/cp-128-3087-5cecd-2.html
- https://tvn.twcert.org.tw/taiwanvn/TVN-201909003
More from Openfind
View All →Affected Vendor
Openfind
View all reports →