First published: Wed Apr 24 2019(Updated: )
SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mailing lists.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SmarterTools SmarterMail | >=16.0.6345<16.3.6985 | |
>=16.0.6345<16.3.6985 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2019-7212.
The severity of CVE-2019-7212 is high with a CVSS score of 8.2.
CVE-2019-7212 affects SmarterTools SmarterMail versions 16.x before build 6985 by allowing an unauthenticated attacker to access other users' emails and file attachments, as well as interact with mailing lists.
An attacker can exploit CVE-2019-7212 by leveraging the hardcoded secret keys in SmarterMail to gain unauthorized access.
Yes, SmarterTools has released a fix for CVE-2019-7212 in build 6985 of SmarterMail 16.x.