Vulnerabilities (CVE)

Filtered by vendor Mailenable Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-12927 1 Mailenable 1 Mailenable 2019-07-23 4.3 MEDIUM 6.1 MEDIUM
MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was possible to hijack the session cookie by exploiting this vulnerability.
CVE-2019-12923 1 Mailenable 1 Mailenable 2019-07-16 4.3 MEDIUM 6.5 MEDIUM
In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from the request. This could allow an attacker to manipulate a user into unwittingly performing actions within the application (such as sending email, adding contacts, or changing settings) on behalf of the attacker.
CVE-2015-9279 1 Mailenable 1 Mailenable 2019-01-17 4.3 MEDIUM 6.1 MEDIUM
MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.