VulnerabilityModified
CVE-2012-0389
Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.53, and 6.x before 6.03 allows remote attackers to inject arbitrary web script or HTML via the Username…
MEDIUM 4.3EPSS 8.12%
Does this matter?
Lower severity and a low EPSS score (8.12%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.53, and 6.x before 6.03 allows remote attackers to inject arbitrary web script or HTML via the Username parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 8.12% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- mailenable/mailenable
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2012-01/0090.htmlExploit
- http://osvdb.org/78242
- http://secunia.com/advisories/47518Vendor Advisory
- http://secunia.com/advisories/47562Vendor Advisory
- http://www.exploit-db.com/exploits/18447
- http://www.mailenable.com/kb/Content/Article.asp?ID=me020567Patch, Vendor Advisory
- http://www.nerv.fi/CVE-2012-0389.txtExploit
- http://www.securityfocus.com/bid/51401Exploit
- http://www.securitytracker.com/id?1026519Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72380
- http://archives.neohapsis.com/archives/bugtraq/2012-01/0090.htmlExploit
- http://osvdb.org/78242
- http://secunia.com/advisories/47518Vendor Advisory
- http://secunia.com/advisories/47562Vendor Advisory
- http://www.exploit-db.com/exploits/18447
- http://www.mailenable.com/kb/Content/Article.asp?ID=me020567Patch, Vendor Advisory
- http://www.nerv.fi/CVE-2012-0389.txtExploit
- http://www.securityfocus.com/bid/51401Exploit
- http://www.securitytracker.com/id?1026519Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72380
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.