Vulnerability Description
SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mailing lists.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Smartertools | Smartermail | >= 16.0.6345, < 16.3.6985 |
Related Weaknesses (CWE)
References
- https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabiThird Party Advisory
- https://www.smartertools.com/smartermail/release-notes/currentExploitRelease NotesVendor Advisory
- https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabiThird Party Advisory
- https://www.smartertools.com/smartermail/release-notes/currentExploitRelease NotesVendor Advisory
FAQ
What is CVE-2019-7212?
CVE-2019-7212 is a vulnerability with a CVSS score of 8.2 (HIGH). SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mail...
How severe is CVE-2019-7212?
CVE-2019-7212 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-7212?
Check the references section above for vendor advisories and patch information. Affected products include: Smartertools Smartermail.