XML External Entity Injection Vulnerability in MailEnable Enterprise Premium
CVE-2019-12924
9.8CRITICAL
What is CVE-2019-12924?
MailEnable Enterprise Premium version 10.23 is susceptible to XML External Entity Injection (XXE) attacks, allowing unauthenticated users to exploit a flaw in the XML processor’s configuration. This could grant attackers access to read arbitrary files on the server, including a cleartext file that stores sensitive credentials for all users. This exploitation not only risks user credential theft but also exposes the system to further attacks against privileged accounts.
