CVE-2015-9280

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
16/01/2019
Last modified:
03/10/2019

Description

MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mailenable:mailenable:*:*:*:*:standard:*:*:* 8.60 (excluding)