CVE-2019-10229
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2019
Last modified:
24/08/2020
Description
An issue was discovered in MailStore Server (and Service Provider Edition) 9.x through 11.x before 11.2.2. When the directory service (for synchronizing and authenticating users) is set to Generic LDAP, an attacker is able to login as an existing user with an arbitrary password on the second login attempt.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mailstore:mailstore:*:*:*:*:service_provider:*:*:* | 9.6 (including) | 11.2.1 (including) |
| cpe:2.3:a:mailstore:mailstore_server:*:*:*:*:*:*:*:* | 9.6 (including) | 11.2.1 (including) |
To consult the complete list of CPE names with products and versions, see this page



