CVE-2019-19497: XSS
MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19497?
CVE-2019-19497 is a vulnerability in MDaemon Email Server 17.5.1 that allows cross-site scripting (XSS) attacks via the filename of an attachment to an email message.
How severe is CVE-2019-19497?
CVE-2019-19497 has a severity rating of medium with a CVSS score of 5.4.
How does CVE-2019-19497 affect MDaemon Email Server?
CVE-2019-19497 affects MDaemon Email Server 17.5.1 by allowing cross-site scripting attacks through the filename of an attachment in an email message.
What is the Common Weakness Enumeration (CWE) for CVE-2019-19497?
The CWE for CVE-2019-19497 is CWE-79, which is a vulnerability related to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
Are there any references or sources related to CVE-2019-19497?
Yes, you can find more information about CVE-2019-19497 on the GitHub repository at https://github.com/Dmitriy-area51/Exploit/blob/master/CVE-2019-19497/README.md and on the Twitter profile of Dmitriy_Area51 at https://twitter.com/Dmitriy_Area51.