CVE-2019-15071

MEDIUM

MAIL2000 6.0-7.0 - Unauthenticated Stored Cross-Site Scripting via ACTION Parameter

Title source: llm
STIX 2.1

Description

The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail system of governments, organizations, companies and universities.

Scores

CVSS v3 6.1
EPSS 0.0163
EPSS Percentile 74.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
openfind/mail2000 6.0 - 7.0
Published Nov 20, 2019
Tracked Since Feb 18, 2026