CVE-2019-7212

HIGH

SmarterTools SmarterMail <16.x-6985 - Info Disclosure

Title source: llm
STIX 2.1

Description

SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mailing lists.

References (2)

Core 2
Core References
Exploit, Release Notes, Vendor Advisory x_refsource_confirm
https://www.smartertools.com/smartermail/release-notes/current

Scores

CVSS v3 8.2
EPSS 0.0101
EPSS Percentile 58.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Details

CWE
CWE-798
Status published
Products (1)
smartertools/smartermail 16.0.6345 - 16.3.6985
Published Apr 24, 2019
Tracked Since Feb 18, 2026