MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers to bypass authentication checks by reusing AuthenticationToken cookies generated for low-privileged users. Attackers can obtain a token from the WebMail login endpoint using the PersistentLogin parameter and replay it against the WebAdmin portal to perform highly privileged administrative actions.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMailenable
APPMailenable< 10.56
Related vulnerabilities
XSS umożliwiający RCE w MailEnable przed wersją 10
XXE w MailEnable Enterprise Premium — kradzież danych uwierzytelniających
Path Traversal w MailEnable — odczyt, upload i usuwanie plików innych użytkowników
XXE w MailEnable — wstrzyknięcie zewnętrznej jednostki XML przez parametr Options
MailEnable: privilege escalation przez błędną obsługę znaku %0A w AUTH.TAB