CVE-2019-12925: Path Traversal
MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated users could add, remove, or potentially read files in arbitrary folders accessible by the IIS user. This could lead to reading other users' credentials including those of SYSADMIN accounts, reading other users' emails, or adding emails or files to other users' accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12925?
CVE-2019-12925 is considered a critical vulnerability due to its potential impact on file integrity and confidentiality.
How do I fix CVE-2019-12925?
To address CVE-2019-12925, it is recommended to upgrade to MailEnable Enterprise Premium version 10.24 or later.
What types of issues does CVE-2019-12925 expose?
CVE-2019-12925 exposes multiple directory traversal issues that allow authenticated users to access arbitrary files.
Who is affected by CVE-2019-12925?
Users of MailEnable Enterprise Premium versions between 6.0 and 10.23 are affected by CVE-2019-12925.
What are the potential risks of CVE-2019-12925?
The risks of CVE-2019-12925 include unauthorized access to sensitive files and credentials, potentially compromising system security.