CVE-2019-15071
The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication.
Does this matter?
Lower severity and a low EPSS score (1.63%). Track it; it rarely justifies an emergency change on its own.
Description
The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail system of governments, organizations, companies and universities.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.63% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- openfind/mail2000
- Source
- twcert@cert.org.tw
References
- https://gist.github.com/chtsecurity/21119b393640bea1d010ab9e3bee216dThird Party Advisory
- https://gist.github.com/tonykuo76/95638395e0c83e68dbd3db0fa0184e27Third Party Advisory
- https://tvn.twcert.org.tw/taiwanvn/TVN-201909001Third Party Advisory
- https://www.chtsecurity.com/download/5011077112c76fb73f82d7eeb2b41b3bcd06c5037be242fec7b185603ca52dc1.txtThird Party Advisory
- https://www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-004.pdf
- https://www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-005.pdf
- https://www.openfind.com.tw/taiwan/resource.htmlProduct, Vendor Advisory
- https://www.twcert.org.tw/en/cp-128-3085-45bda-2.htmlThird Party Advisory
- https://gist.github.com/chtsecurity/21119b393640bea1d010ab9e3bee216dThird Party Advisory
- https://gist.github.com/tonykuo76/95638395e0c83e68dbd3db0fa0184e27Third Party Advisory
- https://tvn.twcert.org.tw/taiwanvn/TVN-201909001Third Party Advisory
- https://www.chtsecurity.com/download/5011077112c76fb73f82d7eeb2b41b3bcd06c5037be242fec7b185603ca52dc1.txtThird Party Advisory
- https://www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-004.pdf
- https://www.openfind.com.tw/taiwan/download/m2k/patch/Openfind_OF-ISAC-19-005.pdf
- https://www.openfind.com.tw/taiwan/resource.htmlProduct, Vendor Advisory
- https://www.twcert.org.tw/en/cp-128-3085-45bda-2.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.