The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any parameter. This vulnerability affects many mail system of governments, organizations, companies and universities.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2019-11-20T04:16:18.705244Z

Updated: 2024-09-17T01:37:01.538Z

Reserved: 2019-08-15T00:00:00

Link: CVE-2019-15072

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-11-20T05:15:12.887

Modified: 2019-11-22T00:50:58.023

Link: CVE-2019-15072

cve-icon Redhat

No data.