« Volver al listado

CVE-2019-15072

Estado: ModificadaMedia (6.1)—

The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any parameter. This vulnerability affects many mail system of governments, organizations, companies and universities.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-15072",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "twcert@cert.org.tw",
      "affectedData": [
        {
          "vendor": "Openfind",
          "product": "MAIL2000",
          "versions": [
            {
              "status": "affected",
              "version": "6.0",
              "lessThan": "Before 20190919",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.0",
              "lessThan": "SP4 Patch 076",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-11-20T05:15:12.887",
  "references": [
    {
      "url": "https://gist.github.com/chtsecurity/b3396500d4686ad47fb26f64967ef24a",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://gist.github.com/tonykuo76/5bf1ac369d953d5276afe0a2d04c2147",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://tvn.twcert.org.tw/taiwanvn/TVN-201909002",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.chtsecurity.com/download/0837ce00c27c73dd3ba3a0d4a7df3a41aaea1ac1e9831a5d61bb64ed484a3598.txt",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.openfind.com.tw/taiwan/resource.html",
      "tags": [
        "Product",
        "Vendor Advisory"
      ],
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.twcert.org.tw/en/cp-128-3086-ff35d-2.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://gist.github.com/chtsecurity/b3396500d4686ad47fb26f64967ef24a",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://gist.github.com/tonykuo76/5bf1ac369d953d5276afe0a2d04c2147",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://tvn.twcert.org.tw/taiwanvn/TVN-201909002",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.chtsecurity.com/download/0837ce00c27c73dd3ba3a0d4a7df3a41aaea1ac1e9831a5d61bb64ed484a3598.txt",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.openfind.com.tw/taiwan/resource.html",
      "tags": [
        "Product",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.twcert.org.tw/en/cp-128-3086-ff35d-2.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "twcert@cert.org.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The login feature in \"/cgi-bin/portal\" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any parameter. This vulnerability affects many mail system of governments, organizations, companies and universities."
    },
    {
      "lang": "es",
      "value": "La funcionalidad de inicio de sesión en \"/cgi-bin/portal\" en MAIL2000 versiones hasta 6.0 y 7.0, tiene una vulnerabilidad de tipo cross-site scripting (XSS), permitiendo una ejecución de código arbitrario por medio de cualquier parámetro. Esta vulnerabilidad afecta a muchos sistemas de correo de gobiernos, organizaciones, empresas y universidades."
    }
  ],
  "lastModified": "2026-06-17T02:19:38.933",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:openfind:mail2000:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8EB23C85-2651-4BE9-A172-540DA4EC3F8B",
              "versionEndIncluding": "7.0",
              "versionStartIncluding": "6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "twcert@cert.org.tw"
}