Back to Database
Status published
Medium
CVE-2019-5966
Joruri Mail 2.1.4 and earlier does not properly manage sessions,...
Vulnerability Description
Joruri Mail 2.1.4 and earlier does not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and alter/disclose the information via unspecified vectors.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-5966
Credits & Attribution
No credits recorded in the NVD database.
More from SiteBridge Inc.
View All →CVE-2023-27888
Cross-site scripting vulnerability in Joruri Gw Ver 3.2.5 and earlier...
Unknown
0
CVE-2019-5967
Cross-site scripting vulnerability in Joruri CMS 2017 Release2 and earlier...
Medium
6.1
CVE-2019-5965
Open redirect vulnerability in Joruri Mail 2.1.4 and earlier allows...
Medium
6.1
CVE-2018-0568
Unrestricted file upload vulnerability in SiteBridge Inc. Joruri Gw Ver...
High
8.8
Affected Vendor
SiteBridge Inc.
View all reports →Affected Software
Joruri Mail
Vulnerable Versions:
2.1.4 and earlier
Timeline
Official Publish:
July 5th, 2019
Last Modified:
August 4th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.