CVE-2015-9278

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
16/01/2019
Last modified:
01/02/2019

Description

MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB after a password-change request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mailenable:mailenable:*:*:*:*:*:*:*:* 8.60 (excluding)