CVE-2019-7212
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
24/04/2019
Last modified:
10/02/2020
Description
SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mailing lists.
Impact
Base Score 3.x
8.20
Severity 3.x
HIGH
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:* | 16.0.6345 (including) | 16.3.6985 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



