CVE-2019-12923: Mailenable

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from the request. This could allow an attacker to manipulate a user into unwittingly performing actions within the application (such as sending email, adding contacts, or changing settings) on behalf of the attacker.

Affected products

  • Mailenable Mailenable: from 6.0, before 6.90 (fixed in 6.90); from 7.0, before 7.62 (fixed in 7.62); from 8.00, before 8.64 (fixed in 8.64); from 9.0, before 9.83 (fixed in 9.83); from 10.00, before 10.24 (fixed in 10.24)

Published 2019-07-08. Last modified 2026-06-17.