« Back to list

CVE-2019-12923

Status: ModifiedMedium (6.5)—

In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from the request. This could allow an attacker to manipulate a user into unwittingly performing actions within the application (such as sending email, adding contacts, or changing settings) on behalf of the attacker.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2019-12923",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-07-08T21:15:09.957",
  "references": [
    {
      "url": "http://www.mailenable.com/Premium-ReleaseNotes.txt",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabilities-in-mailenable/",
      "tags": [
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.mailenable.com/Premium-ReleaseNotes.txt",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabilities-in-mailenable/",
      "tags": [
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from the request. This could allow an attacker to manipulate a user into unwittingly performing actions within the application (such as sending email, adding contacts, or changing settings) on behalf of the attacker."
    },
    {
      "lang": "es",
      "value": "En MailEnable Enterprise Premium versión 10.23, el mecanismo de protección contra un potencial problema de tipo cross-site request forgery (CSRF) no se implementó correctamente y fue posible omitirlo eliminando el parámetro token anti-CSRF de la petición. Esto podría permitir a un atacante manipular a un usuario para que, involuntariamente, realice acciones dentro de la aplicación (tales como enviar correos electrónicos, agregar contactos o cambiar la configuración) en nombre del atacante."
    }
  ],
  "lastModified": "2026-06-17T02:15:43.757",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:premium:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7B4998A-BD40-4D0D-AC78-0457F40067C0",
              "versionEndExcluding": "6.90",
              "versionStartIncluding": "6.0"
            },
            {
              "criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:premium:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B9FFD5C-6982-4B54-BED3-DBAF30490439",
              "versionEndExcluding": "7.62",
              "versionStartIncluding": "7.0"
            },
            {
              "criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:premium:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FAD50A0-D3E4-40B7-80DB-AD741B1BE1E6",
              "versionEndExcluding": "8.64",
              "versionStartIncluding": "8.00"
            },
            {
              "criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:premium:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5DCC3F1A-6A49-4A2B-B973-1A44EFEF675B",
              "versionEndExcluding": "9.83",
              "versionStartIncluding": "9.0"
            },
            {
              "criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:premium:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "55F2A0A6-2BA0-4176-B9A2-9E2A86635BC2",
              "versionEndExcluding": "10.24",
              "versionStartIncluding": "10.00"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}