CVE-2015-9280: XEE
Published Jan 16, 2019
·Updated
MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.
Affected Software
1 affected component
MailEnable MailEnable<8.60
Event History
Jan 16, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9280?
CVE-2015-9280 has a medium severity rating due to the potential for XML External Entity (XXE) attacks.
2
How do I fix CVE-2015-9280?
To fix CVE-2015-9280, upgrade MailEnable to version 8.60 or later.
3
What kind of vulnerability is CVE-2015-9280?
CVE-2015-9280 is an XML External Entity (XXE) vulnerability that allows the processing of malicious XML documents.
4
What is the impact of CVE-2015-9280 on my system?
The impact of CVE-2015-9280 can include unauthorized data access and potential exposure of sensitive information.
5
Is CVE-2015-9280 exploitable remotely?
Yes, CVE-2015-9280 is exploitable remotely through a crafted XML document sent in the request.