CVE-2019-7212

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
24/04/2019
Last modified:
10/02/2020

Description

SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mailing lists.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:* 16.0.6345 (including) 16.3.6985 (excluding)