Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component
An attacker exploits the vulnerable failure.aspx component, to which it is possible to submit a malicious payload without authentication and without user interaction on the server side. The injected XSS code is then executed in the context of the application, which according to the description can lead to arbitrary code execution (RCE). The attack is possible remotely over the network, without special privileges or complex conditions.
An attacker can execute arbitrary code in the context of the application or victim's browser, potentially leading to system takeover, data theft, or further lateral movement in the network.
MailEnable should be updated to version 10 or newer according to vendor information available at mailenable.com
MailEnable in all versions before version 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMailenable
APPMailenable< 10.00
Related vulnerabilities
XXE w MailEnable Enterprise Premium — kradzież danych uwierzytelniających
Path Traversal w MailEnable — odczyt, upload i usuwanie plików innych użytkowników
MailEnable: privilege escalation przez błędną obsługę znaku %0A w AUTH.TAB
XXE w MailEnable — wstrzyknięcie zewnętrznej jednostki XML przez parametr Options
MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdm...