ZeroHour

CVE-2019-7212

PoC
CVSS 3.0
8.2 high
EPSS
1%p61
Published
()
Modified
Description

SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mailing lists.

Vendors
smartertools
Products
smartermail
Weakness
CWE-798
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.