CVE-2019-12923: CSRF
In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from the request. This could allow an attacker to manipulate a user into unwittingly performing actions within the application (such as sending email, adding contacts, or changing settings) on behalf of the attacker.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12923?
CVE-2019-12923 has a medium severity level due to its potential for cross-site request forgery (CSRF).
How do I fix CVE-2019-12923?
To fix CVE-2019-12923, upgrade MailEnable Enterprise Premium to version 10.24 or later where the CSRF protection mechanism is correctly implemented.
What vulnerabilities does CVE-2019-12923 exploit?
CVE-2019-12923 exploits the improper implementation of CSRF protection allowing removal of the anti-CSRF token parameter.
Which versions of MailEnable are affected by CVE-2019-12923?
MailEnable versions from 6.0 to 10.23 are affected by CVE-2019-12923.
Can CVE-2019-12923 lead to unauthorized actions?
Yes, CVE-2019-12923 can allow an attacker to perform unauthorized actions by tricking a user into unwittingly submitting requests.