CVE-2019-7212
8.2
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Exploitability: 3.9 / Impact: 4.2
Source: NVD
Description
SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mailing lists.
Affected (1)
Products: Smartertools: Smartermail
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 16.0.6345 to 16.3.6985 |
References (4)
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
ExploitRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitRelease NotesVendor Advisory
Timeline
No history available yet.