CVE-2019-15071
MEDIUMMAIL2000 6.0-7.0 - Unauthenticated Stored Cross-Site Scripting via ACTION Parameter
Title source: llmDescription
The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail system of governments, organizations, companies and universities.
References (8)
Core 8
Core References
Third Party Advisory x_refsource_confirm
https://gist.github.com/tonykuo76/95638395e0c83e68dbd3db0fa0184e27
Product, Vendor Advisory x_refsource_confirm
https://www.openfind.com.tw/taiwan/resource.html
Third Party Advisory x_refsource_confirm
https://gist.github.com/chtsecurity/21119b393640bea1d010ab9e3bee216d
Third Party Advisory x_refsource_confirm
https://www.chtsecurity.com/download/5011077112c76fb73f82d7eeb2b41b3bcd06c5037be242fec7b185603ca52dc1.txt
Third Party Advisory x_refsource_confirm
https://www.twcert.org.tw/en/cp-128-3085-45bda-2.html
Third Party Advisory x_refsource_confirm
https://tvn.twcert.org.tw/taiwanvn/TVN-201909001
Various Sources x_refsource_misc
https://www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-004.pdf
Various Sources x_refsource_misc
https://www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-005.pdf
Scores
CVSS v3
6.1
EPSS
0.0163
EPSS Percentile
74.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
openfind/mail2000
6.0 - 7.0
Published
Nov 20, 2019
Tracked Since
Feb 18, 2026